AUGUST 21, 2026
Live Feed
Back to database
Case File

CVE-2026-72745

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

FreeRDP versions prior to 3.30.0 are vulnerable to an out-of-bounds error in the kerberos_DecryptMessage() function, which allows a malicious peer to exploit the EC field of a GSS Wrap token during CredSSP/NLA authentication. This vulnerability can lead to information disclosure, memory corruption, or denial of service due to improper bounds checking in pointer arithmetic. Organizations using FreeRDP should prioritize patching this vulnerability to mitigate potential security risks.

CVE
CVE-2026-72745
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A

Original NVD Description

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-73242.