{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3afreerdpfreerdp/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.3,"id":"CVE-2026-91949"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FreeRDP (\u003c 3.31.0)"],"_cs_severities":["high"],"_cs_tags":["memory-corruption","rdp","vulnerability","denial-of-service","cve-2026-91955"],"_cs_type":"advisory","_cs_vendors":["FreeRDP"],"content_html":"\u003cp\u003eFreeRDP server versions prior to 3.31.0 contain a protocol negotiation bypass vulnerability, tracked as CVE-2026-91949. This flaw allows unauthenticated remote attackers to force an RDP session into RDSTLS mode, even when the server configuration is explicitly set to disable RDSTLS. By sending specifically crafted, incompatible protocol negotiation requests, an attacker triggers a negotiation failure that leads the server to incorrectly fall back or proceed into an insecure RDSTLS handshake. This vulnerability effectively bypasses pre-authentication security restrictions and transport-level policy enforcement. Given the potential for unauthenticated access to the underlying protocol layer, this issue poses a high risk to organizations relying on FreeRDP to enforce strict transport security for remote access services. Organizations should update to version 3.31.0 or later to mitigate this risk.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to establish RDSTLS connections in environments where such transport is explicitly prohibited by security policy. This bypasses access controls designed to limit protocol exposure, potentially exposing the server to further pre-authentication exploitation vectors and unauthorized remote connectivity.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate all instances of FreeRDP server to version 3.31.0 or later to ensure the protocol negotiation logic correctly enforces transport policies. Since the vulnerability involves protocol-level manipulation, monitor RDP connection logs for unusual negotiation error patterns or unexpected TLS handshake initiations originating from unauthorized external networks.\u003c/p\u003e\n","date_modified":"2026-09-15T17:44:09Z","date_published":"2026-09-15T17:41:49Z","id":"https://feed.craftedsignal.io/briefs/2026-09-freerdp-bypass/","summary":"An unauthenticated protocol negotiation vulnerability in FreeRDP servers allows attackers to bypass RDSTLS transport security policies.","title":"FreeRDP Protocol Negotiation Bypass via CVE-2026-91949","url":"https://feed.craftedsignal.io/briefs/2026-09-freerdp-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}