SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-66401

LOW · CVSS 2.1 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-01 · Last synced 2026-08-31

CyberRota Analysis

AI-Generated

FreeRDP versions prior to 3.29.0 are vulnerable to an out-of-bounds heap read due to improper validation of descriptor lengths in the UVC H.264 extension-unit parser. This flaw allows a local attacker to exploit a malicious USB video camera, potentially leading to a denial of service during camera stream setup. Organizations utilizing FreeRDP with USB video camera integration should prioritize patching to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-66401
Severity
LOW
CVSS
2.1
EPSS
0.15%

Original NVD Description

FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID field. A local attacker with a malicious USB video camera can trigger a heap read beyond allocated bounds during camera stream setup, causing denial of service.