CVE-2026-25953 | FreeRDP up to 3.22.x xf_AppUpdateWindowFromSurface use after free (GHSA-p6rq-rxpc-rh3p / WID-SEC-2026-0514)
A vulnerability categorized as critical has been discovered in FreeRDP up to 3.22.x. This affects the function xf_AppUpdateWindowFromSurface. Executing a manipulation can lead to use after free.
This vulnerability is handled as CVE-2026-25953. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.