<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3afreerdpfreerdp/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 15 Sep 2026 17:41:49 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3afreerdpfreerdp/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>FreeRDP Protocol Negotiation Bypass via CVE-2026-91949</title><link>https://feed.craftedsignal.io/briefs/2026-09-freerdp-bypass/</link><pubDate>Tue, 15 Sep 2026 17:41:49 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-freerdp-bypass/</guid><description>An unauthenticated protocol negotiation vulnerability in FreeRDP servers allows attackers to bypass RDSTLS transport security policies.</description><content:encoded><![CDATA[<p>FreeRDP server versions prior to 3.31.0 contain a protocol negotiation bypass vulnerability, tracked as CVE-2026-91949. This flaw allows unauthenticated remote attackers to force an RDP session into RDSTLS mode, even when the server configuration is explicitly set to disable RDSTLS. By sending specifically crafted, incompatible protocol negotiation requests, an attacker triggers a negotiation failure that leads the server to incorrectly fall back or proceed into an insecure RDSTLS handshake. This vulnerability effectively bypasses pre-authentication security restrictions and transport-level policy enforcement. Given the potential for unauthenticated access to the underlying protocol layer, this issue poses a high risk to organizations relying on FreeRDP to enforce strict transport security for remote access services. Organizations should update to version 3.31.0 or later to mitigate this risk.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to establish RDSTLS connections in environments where such transport is explicitly prohibited by security policy. This bypasses access controls designed to limit protocol exposure, potentially exposing the server to further pre-authentication exploitation vectors and unauthorized remote connectivity.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update all instances of FreeRDP server to version 3.31.0 or later to ensure the protocol negotiation logic correctly enforces transport policies. Since the vulnerability involves protocol-level manipulation, monitor RDP connection logs for unusual negotiation error patterns or unexpected TLS handshake initiations originating from unauthorized external networks.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>memory-corruption</category><category>rdp</category><category>vulnerability</category><category>denial-of-service</category><category>cve-2026-91955</category></item></channel></rss>