Improper Certificate Validation in FreeRDP - CVE-2026-66402
Published: July 16, 2026 / Updated: September 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass TLS server identity validation.
The vulnerability exists due to improper certificate validation in x509_utils_get_dns_names() when parsing DNS subject alternative name values containing embedded NUL bytes. A remote attacker can present a specially crafted certificate to bypass TLS server identity validation.
Exploitation requires a certificate chain trusted by the FreeRDP client.