LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-26986

CVE-2026-26986 - Vulnerability Analysis

HighCVSS: 7.5

Last Updated: February 27, 2026

FreeRDP - Use After Free

Published: February 25, 2026Updated: February 27, 2026PoC AvailableRemote Exploitable

Overview

FreeRDP prior to 3.23.0 contains a use-after-free vulnerability caused by dereferencing a freed xfAppWindow pointer during HashTable_Free cleanup, letting remote attackers cause a denial of service, exploit requires disconnect event.

Severity & Score

Severity: High
CVSS Score: 7.5
EPSS Score: 7.0%(Probability of exploitation in next 30 days)

Impact

Attackers can cause a denial of service by crashing the application due to use-after-free.

Mitigation

Update to version 3.23.0 or later.

Social Media Activity(1 post)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 1, 2026

🟠 CVE-2026-26986 - High (7.5) FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `rail_window_free` dereferences a freed `xfAppWindow` pointer during `HashTable_Free` cleanup because `xf_rail_window_common` calls `free(appWindow)` on titl... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-26986/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-26986
Severity
High
CVSS Score
7.5
Type
use_after_free
Status
confirmed
EPSS
7.0%
Social Posts
1

CWE

  • CWE-416

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Score

7.0%Probability of exploitation in the next 30 days