Applications
CVE-2026-72746
8.7
High
EPSS n/aAug 11, 2026
Auth bypass in FreeRDP RDSTLS allows unauthenticated RDP session establishment.
This CVE has been withdrawn. NVD marks this identifier as Rejected, which means it was a duplicate or turned out not to be a vulnerability. The analysis below is kept for reference only — do not act on it.
executive summary
technical analysis
affected
FreeRDP 3.x (e.g., 3.27.1)FreeRDP master HEADServers with RdstlsSecurity = TRUE
impact
Remote unauthenticated attacker can bypass RDSTLS auth and obtain an authenticated RDP session, enabling access and lateral movement.
action required
Immediate action required
how to fix
Remediation steps are tailored for users whose stack is affected. Add this technology to your stack to see the fix checklist.
references