CVE-2026-72746: FreeRDP before 3.30.0 RDSTLS Server Authentication Bypass via PDU-type Confusion
Published Aug 11, 2026
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-73241.
Affected Software
1 affected component
FreeRDP freerdp<3.30.0
Event History
Aug 11, 2026
CVE Published
via MITRE·12:17 PM
Rejected
via MITRE·12:17 PM
Data Sourced
via NVD·01:19 PM
Description
Aug 12, 2026
Rejected
via MITRE·04:58 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-72746?
CVE-2026-72746 has a severity rating of high with a score of 7.5.
2
How do I fix CVE-2026-72746?
To mitigate CVE-2026-72746, upgrade FreeRDP to version 3.30.0 or later.
3
What type of vulnerability is CVE-2026-72746?
CVE-2026-72746 is a server-side authentication bypass vulnerability during the RDSTLS handshake.
4
What systems are affected by CVE-2026-72746?
CVE-2026-72746 affects FreeRDP versions prior to 3.30.0.
5
What does CVE-2026-72746 exploit?
CVE-2026-72746 exploits an issue where the server does not verify the required PDU during the RDSTLS handshake.