THREATOPS
THREAT OPSThreat News › FreeRDP <= 3.30.0: five server-side vulnerabilities fixed in 3.31.0, pre-auth RCE demonstrated

FreeRDP <= 3.30.0: five server-side vulnerabilities fixed in 3.31.0, pre-auth RCE demonstrated

lowoss_secPublished 2026-09-01

<p>Posted by Samuel Page on Sep 01</p>FreeRDP 3.31.0 (2026-08-26) fixes 5 vulnerabilities in FreeRDP&apos;s server role<br /> that Bynario reported, as well as 17 other security issues. We were able to<br /> demonstrate that 3 of the issues could be chained to achieve pre-auth remote<br /> code execution, however we believe exposure to this specific chain is limited<br /> (more detail below).<br /

MITRE ATT&CK techniques

Original source: https://seclists.org/oss-sec/2026/q3/633