CVE-2026-91948
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTI
CVSS
7.5
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 15, 2026 · Last modified: Sep 16, 2026 · CWE-191
Not enough EPSS history yet.
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution.
- github.comhttps://github.com/FreeRDP/FreeRDP/commit/40d9202cd95551600c07437ce6bd5ecd7d31e57b
- github.comhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9jcm-x588-gh26
- www.vulncheck.comhttps://www.vulncheck.com/advisories/freerdp-before-3.31.0-out-of-bounds-write-via-show-protocol
- github.comhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9jcm-x588-gh26
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-890287.5 HIG—
———MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by supplying a crafted uniPwdLen value in the SMB1 SessionSetupAndX handler. An attacker can send a malformed SMB1 request with a uniPwdLen field that triggers an integer underflow, causing the resulting value to be used as the copy length in a memory copy operation into a smaller heap buffer, corrupting adjacent heap memory.7hCVE-2026-909964.0 MED1.5%
——0A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS responder to become unstable or terminate. This vulnerability affects the availability of the system responder.5hCVE-2026-13326—4.8%
——1An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure via a crafted NFC tag.5dCVE-2026-819775.5 MED7.0%
——2Acrobat Reader is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.5dCVE-2026-663077.5 HIG49.1%
——15Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.8dCVE-2026-784536.5 MED58.4%
——18Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.5d