freerdp3 vulnerabilities (CVE-2026-27951)
Multiple security vulnerabilities were discovered in FreeRDP (freerdp3) that could allow an attacker to obtain sensitive information, cause a denial of service by crashing the application, or execute arbitrary code. These issues affect various specific package versions of freerdp3 on Ubuntu 24.04 LTS and 26.04 LTS. A security update has been released by Ubuntu to address these vulnerabilities by upgrading to freerdp3 version 3.30.0+dfsg-0ubuntu0 for the affected releases.
AI Analysis
Technical Summary
FreeRDP (freerdp3) contains multiple security issues that could be exploited to obtain sensitive information, cause application crashes leading to denial of service, or execute arbitrary code. The vulnerabilities affect numerous specific package versions on Ubuntu 24.04 LTS and 26.04 LTS. Ubuntu has released updated packages (version 3.30.0+dfsg-0ubuntu0) that include fixes for these issues. The update is available via standard system updates. No CVSS score is provided, and no known exploits in the wild have been reported at this time.
Potential Impact
An attacker exploiting these vulnerabilities could potentially gain access to sensitive information, disrupt service by causing FreeRDP to crash, or execute arbitrary code on affected systems. This could lead to unauthorized access or denial of service conditions on systems running vulnerable versions of freerdp3.
Mitigation Recommendations
A security update is available and should be applied to affected systems. Ubuntu has released patched versions of freerdp3 (3.30.0+dfsg-0ubuntu0) for Ubuntu 24.04 LTS and 26.04 LTS. Applying the standard system update will install these fixes and mitigate the vulnerabilities. Users should follow Ubuntu's security notice USN-8561-1 for update instructions.
freerdp3 vulnerabilities (CVE-2026-27951)
Description
Multiple security vulnerabilities were discovered in FreeRDP (freerdp3) that could allow an attacker to obtain sensitive information, cause a denial of service by crashing the application, or execute arbitrary code. These issues affect various specific package versions of freerdp3 on Ubuntu 24.04 LTS and 26.04 LTS. A security update has been released by Ubuntu to address these vulnerabilities by upgrading to freerdp3 version 3.30.0+dfsg-0ubuntu0 for the affected releases.
Affected software
pkg:deb/ubuntu/freerdp3?arch=source&distro=noblepkg:deb/ubuntu/freerdp3?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
FreeRDP (freerdp3) contains multiple security issues that could be exploited to obtain sensitive information, cause application crashes leading to denial of service, or execute arbitrary code. The vulnerabilities affect numerous specific package versions on Ubuntu 24.04 LTS and 26.04 LTS. Ubuntu has released updated packages (version 3.30.0+dfsg-0ubuntu0) that include fixes for these issues. The update is available via standard system updates. No CVSS score is provided, and no known exploits in the wild have been reported at this time.
Potential Impact
An attacker exploiting these vulnerabilities could potentially gain access to sensitive information, disrupt service by causing FreeRDP to crash, or execute arbitrary code on affected systems. This could lead to unauthorized access or denial of service conditions on systems running vulnerable versions of freerdp3.
Mitigation Recommendations
A security update is available and should be applied to affected systems. Ubuntu has released patched versions of freerdp3 (3.30.0+dfsg-0ubuntu0) for Ubuntu 24.04 LTS and 26.04 LTS. Applying the standard system update will install these fixes and mitigate the vulnerabilities. Users should follow Ubuntu's security notice USN-8561-1 for update instructions.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- USN-8561-1
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- null
Patch Information
Threat ID: 6a885f2cacd9273b493f8284
Added to database: 08/21/2026, 14:22:36 UTC
Last enriched: 08/21/2026, 14:40:15 UTC
Last updated: 08/21/2026, 22:52:11 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.