AUGUST 21, 2026
Live Feed
Back to database
Case File

CVE-2026-72746

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

FreeRDP versions prior to 3.30.0 are vulnerable to a server-side authentication bypass during the RDSTLS handshake, allowing unauthenticated remote clients to exploit the flaw by sending a Capabilities PDU instead of the required Authentication Request PDU. This results in the server incorrectly treating the session as authenticated, potentially granting unauthorized access to sensitive resources. Organizations using FreeRDP should prioritize addressing this vulnerability to mitigate the risk of unauthorized access to their systems.

CVE
CVE-2026-72746
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A

Original NVD Description

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-73241.