← All Advisories

CVE-2026-66402

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-66402

Key Details

CVECVE-2026-66402
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-10-02
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsfreerdp freerdp
Classified asCWE-295 (Improper Certificate Validation)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
freerdpfreerdp
SubsystemsGeneral OT
SectorsMultiple

What to Know

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common Name and DNS SAN string matching instead of using OpenSSL's length-aware identity validation APIs, it (1) truncates DNS SAN values at embedded NUL bytes (accepting e.g. 'victim.example\0.attacker.example' as 'victim.example'), (2) accepts a matching Common Name even when non-matching DNS SAN entries are present, and (3) accepts IP-literal targets via DNS/CN matching without comparing iPAddress SANs. Under a trusted or misissued certificate chain, an attacker positioned to present such a certificate can bypass server identity verification, weakening TLS server authentication. (NVD)

What to Do

Monitor freerdp's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-66402
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-66402
Vendor advisoryhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-43hh-p3vw-hfx3