CVE-2026-25955 | FreeRDP up to 3.22.x xf_AppUpdateWindowFromSurface use after free (GHSA-4g54-x8v7-559x / Nessus ID 300148)
A vulnerability labeled as critical has been found in FreeRDP up to 3.22.x. Affected by this issue is the function xf_AppUpdateWindowFromSurface. Executing a manipulation can lead to use after free.
The identification of this vulnerability is CVE-2026-25955. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.