SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-57156

CRITICAL · CVSS 9.8 EPSS 0.42% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

FreeRDP clients prior to version 3.28.0 on 32-bit builds are vulnerable to an integer overflow in the update_read_delta_points function, which can be exploited by a malicious RDP peer to allocate an undersized heap buffer, leading to potential heap corruption. This critical vulnerability, with a CVSS score of 9.8, poses a significant risk as it allows attackers to execute arbitrary code or crash the application. Organizations using FreeRDP should prioritize upgrading to version 3.28.0 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-57156
Severity
CRITICAL
CVSS
9.8
EPSS
0.42%

Original NVD Description

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in update_read_delta_points in libfreerdp/core/orders.c when multiplying an attacker-controlled point count by sizeof(DELTA_POINT), allowing a malicious RDP peer to allocate an undersized heap buffer and then write beyond it during initialization. This issue is fixed in version 3.28.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)