FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEARโs NDR array reader does not perform bounds checking on the onโwire element count and can write past the heap buffer allocated from hints, causing a heap buffer overflow in ndr_read_uint8Array. This vulnerability is fixed in 3.20.1.
VulnCheck: FreeRDP is
Vulnerability
CVE-2026-22853
VulnCheck
Refer to CVE-2026-22853 NVD advisory