CVE-2026-91957

FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread creation fails after device registration. Attackers can trigger thread creation failure during channel setup to cause device pointer deallocation while devman retains a reference, leading to crash or code execution.

  • Published Sep 15, 2026
  • CVSS 2.3 low
  • 0.4% chance of exploitation in the next 30 days (EPSS)
  • Public exploit code is available
  • A fix is available

Affected software

CVE-2026-91957 at the National Vulnerability Database