Red Hat Updates FreeRDP for CVE-2026-55193 Across RHEL 8.4 and 8.6 Extended Branches

P1 — VALIDATE AND UPDATEHigh · 8.8 (official CVSS v3.1)EXPLOITATION: NOT STATED

Quick Answer

Red Hat published RHSA-2026:73026 and RHSA-2026:73027 for FreeRDP on entitled RHEL 8.4 and 8.6 AUS or EUS Extension streams. Inventory only entitled systems in the listed branches, apply freerdp-2:2.2.0-14.el8_4.4.src / freerdp-2:2.2.0-7.el8_6.13.src, validate remote-desktop and TS Gateway client workflows, and retain entitlement, package, and change evidence.

Confirm Scope And Apply The Supported Fix

What to do now: Identify entitled systems in the exact advisory branches, confirm the installed source package, apply freerdp-2:2.2.0-14.el8_4.4.src / freerdp-2:2.2.0-7.el8_6.13.src, validate remote-desktop and TS Gateway client workflows, and preserve entitlement, package-manager, service, and test evidence.

Open the authoritative advisory

Last verified: 2026-09-29 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.

Scope And Authority

Product scopeFreeRDP on entitled RHEL 8.4 and 8.6 AUS or EUS Extension streams
AdvisoryRHSA-2026:73026 / RHSA-2026:73027
CVECVE-2026-55193
Authoritative release date2026-09-29 07:06:11 UTC
Authority revision date2026-09-29 10:15:46 UTC
Affected versionsThe RHEL 8.4 and 8.6 AppStream AUS or EUS Extension branches identified by RHSA-2026:73026 and RHSA-2026:73027 before their advisory-listed fixed builds.
Fixed versionfreerdp-2:2.2.0-14.el8_4.4.src / freerdp-2:2.2.0-7.el8_6.13.src
CVSS base score8.8 (official CVSS v3.1)
CVSS severityHigh
Exploitation statusNot stated by the authority; no exploitation claim is inferred.

What Changed

Red Hat corrected a FreeRDP TS Gateway heap-buffer overflow that can crash a client and may permit arbitrary code execution when a client processes a malicious gateway response fragment.

What To Validate Now

  1. Inventory. Locate entitled systems using FreeRDP on entitled RHEL 8.4 and 8.6 AUS or EUS Extension streams; record the RHEL minor stream, repository entitlement, source package, architecture, owner, and dependent applications.
  2. Establish applicability. Match each system to RHSA-2026:73026 and RHSA-2026:73027. The RHEL 8.4 and 8.6 AppStream AUS or EUS Extension branches identified by RHSA-2026:73026 and RHSA-2026:73027 before their advisory-listed fixed builds. Do not generalize this branch-specific fix to other RHEL streams.
  3. Remediate. Apply freerdp-2:2.2.0-14.el8_4.4.src / freerdp-2:2.2.0-7.el8_6.13.src through the matching entitled Red Hat repository and normal change control; Red Hat states that no qualifying workaround is available.
  4. Validate. Confirm the resulting package and repository branch, exercise representative remote-desktop and TS Gateway client workflows, monitor for regressions, and document exceptions or rollback.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

These are branch-specific extended-support fixes. Confirm entitlement and repository configuration before deployment, preserve configuration and rollback options, and do not treat the CVSS score as evidence of exploitation.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.