CVE-2026-26955 | FreeRDP up to 3.22.x gdi_SurfaceCommand_ClearCodec out-of-bounds write (GHSA-mr6w-ch7c-mqqj / Nessus ID 299994)
A vulnerability marked as critical has been reported in FreeRDP up to 3.22.x. Affected is the function gdi_SurfaceCommand_ClearCodec. Performing a manipulation results in out-of-bounds write.
This vulnerability is identified as CVE-2026-26955. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.