Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
RHSA-2026:16866
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2026:16866
Import Source
https://security.access.redhat.com/data/osv/RHSA-2026:16866.json
JSON Data
https://api.osv.dev/v1/vulns/RHSA-2026:16866
Upstream
CVE-2026-25952
CVE-2026-26986
CVE-2026-27951
CVE-2026-29775
CVE-2026-31883
CVE-2026-31884
CVE-2026-31885
CVE-2026-33985
Published
2026-05-13T10:14:26Z
Modified
2026-05-13T10:38:46.068986Z
Severity
7.3 (High)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS Calculator
Summary
Red Hat Security Advisory: freerdp security update
Details
References
https://access.redhat.com/errata/RHSA-2026:16866
https://access.redhat.com/security/updates/classification/#moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2442768
https://bugzilla.redhat.com/show_bug.cgi?id=2442782
https://bugzilla.redhat.com/show_bug.cgi?id=2442783
https://bugzilla.redhat.com/show_bug.cgi?id=2447379
https://bugzilla.redhat.com/show_bug.cgi?id=2447383
https://bugzilla.redhat.com/show_bug.cgi?id=2447385
https://bugzilla.redhat.com/show_bug.cgi?id=2447386
https://bugzilla.redhat.com/show_bug.cgi?id=2453217
https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_16866.json
https://access.redhat.com/security/cve/CVE-2026-25952
https://www.cve.org/CVERecord?id=CVE-2026-25952
https://nvd.nist.gov/vuln/detail/CVE-2026-25952
https://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c#L1167
https://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c#L1174
https://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c#L1178
https://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c#L1230-L1238
https://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c#L643
https://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_window.c#L1111
https://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_window.c#L1128
https://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_window.c#L1394
https://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_window.c#L1428
https://github.com/FreeRDP/FreeRDP/commit/1994e9844212a6dfe0ff12309fef520e888986b5
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-cgqm-cwjg-7w9x
https://access.redhat.com/security/cve/CVE-2026-26986
https://www.cve.org/CVERecord?id=CVE-2026-26986
https://nvd.nist.gov/vuln/detail/CVE-2026-26986
https://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c#L1297
https://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c#L1316-L1327
https://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c#L386-L394
https://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c#L395-L399
https://github.com/FreeRDP/FreeRDP/blob/5c7aae27d0417b42b4806c2a5c583ca39dd9ef1e/client/X11/xf_rail.c#L401-L404
https://github.com/FreeRDP/FreeRDP/commit/b4f0f0a18fe53aa8d47d062f91471f4e9c5e0d51
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-crqx-g6x5-rx47
https://access.redhat.com/security/cve/CVE-2026-27951
https://www.cve.org/CVERecord?id=CVE-2026-27951
https://nvd.nist.gov/vuln/detail/CVE-2026-27951
https://github.com/FreeRDP/FreeRDP/commit/118afc0b954ba9d5632b7836ad24e454555ed113
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-qcfc-ghxr-h927
https://access.redhat.com/security/cve/CVE-2026-29775
https://www.cve.org/CVERecord?id=CVE-2026-29775
https://nvd.nist.gov/vuln/detail/CVE-2026-29775
https://github.com/FreeRDP/FreeRDP/commit/ffad58fd2b329efd81a3239e9d7e3c927b8e503f
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-h666-rfw3-jhvj
https://access.redhat.com/security/cve/CVE-2026-31883
https://www.cve.org/CVERecord?id=CVE-2026-31883
https://nvd.nist.gov/vuln/detail/CVE-2026-31883
https://github.com/FreeRDP/FreeRDP/commit/16df2300e1e3f5a51f68fb1626429e58b531b7c8
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-85x9-4xxp-xhm5
https://access.redhat.com/security/cve/CVE-2026-31884
https://www.cve.org/CVERecord?id=CVE-2026-31884
https://nvd.nist.gov/vuln/detail/CVE-2026-31884
https://github.com/FreeRDP/FreeRDP/commit/03b48b3601d867afccac1cdc6081de7a275edce7
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-jp7m-94ww-p56r
https://access.redhat.com/security/cve/CVE-2026-31885
https://www.cve.org/CVERecord?id=CVE-2026-31885
https://nvd.nist.gov/vuln/detail/CVE-2026-31885
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-h23r-3988-3wf3
https://access.redhat.com/security/cve/CVE-2026-33985
https://www.cve.org/CVERecord?id=CVE-2026-33985
https://nvd.nist.gov/vuln/detail/CVE-2026-33985
https://github.com/FreeRDP/FreeRDP/commit/c49d1ad43b8c7b32794d0250f2623c2dccd7ef25
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-x6gr-8p7h-5h85
Affected packages
Red Hat:rhel_eus:9.4::appstream
freerdp
Package
Name
freerdp
Purl
pkg:rpm/redhat/freerdp
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:2.11.2-1.el9_4.8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:16866.json"
freerdp-debuginfo
Package
Name
freerdp-debuginfo
Purl
pkg:rpm/redhat/freerdp-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:2.11.2-1.el9_4.8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:16866.json"
freerdp-debugsource
Package
Name
freerdp-debugsource
Purl
pkg:rpm/redhat/freerdp-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:2.11.2-1.el9_4.8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:16866.json"
freerdp-devel
Package
Name
freerdp-devel
Purl
pkg:rpm/redhat/freerdp-devel
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:2.11.2-1.el9_4.8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:16866.json"
freerdp-libs
Package
Name
freerdp-libs
Purl
pkg:rpm/redhat/freerdp-libs
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:2.11.2-1.el9_4.8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:16866.json"
freerdp-libs-debuginfo
Package
Name
freerdp-libs-debuginfo
Purl
pkg:rpm/redhat/freerdp-libs-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:2.11.2-1.el9_4.8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:16866.json"
libwinpr
Package
Name
libwinpr
Purl
pkg:rpm/redhat/libwinpr
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:2.11.2-1.el9_4.8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:16866.json"
libwinpr-debuginfo
Package
Name
libwinpr-debuginfo
Purl
pkg:rpm/redhat/libwinpr-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:2.11.2-1.el9_4.8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:16866.json"
libwinpr-devel
Package
Name
libwinpr-devel
Purl
pkg:rpm/redhat/libwinpr-devel
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:2.11.2-1.el9_4.8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:16866.json"
Red Hat:rhel_eus:9.4::crb
freerdp
Package
Name
freerdp
Purl
pkg:rpm/redhat/freerdp
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:2.11.2-1.el9_4.8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:16866.json"
freerdp-debuginfo
Package
Name
freerdp-debuginfo
Purl
pkg:rpm/redhat/freerdp-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:2.11.2-1.el9_4.8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:16866.json"
freerdp-debugsource
Package
Name
freerdp-debugsource
Purl
pkg:rpm/redhat/freerdp-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:2.11.2-1.el9_4.8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:16866.json"
freerdp-devel
Package
Name
freerdp-devel
Purl
pkg:rpm/redhat/freerdp-devel
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:2.11.2-1.el9_4.8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:16866.json"
freerdp-libs
Package
Name
freerdp-libs
Purl
pkg:rpm/redhat/freerdp-libs
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:2.11.2-1.el9_4.8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:16866.json"
freerdp-libs-debuginfo
Package
Name
freerdp-libs-debuginfo
Purl
pkg:rpm/redhat/freerdp-libs-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:2.11.2-1.el9_4.8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:16866.json"
libwinpr
Package
Name
libwinpr
Purl
pkg:rpm/redhat/libwinpr
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:2.11.2-1.el9_4.8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:16866.json"
libwinpr-debuginfo
Package
Name
libwinpr-debuginfo
Purl
pkg:rpm/redhat/libwinpr-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:2.11.2-1.el9_4.8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:16866.json"
libwinpr-devel
Package
Name
libwinpr-devel
Purl
pkg:rpm/redhat/libwinpr-devel
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:2.11.2-1.el9_4.8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:16866.json"
RHSA-2026:16866 - OSV