Red Hat FreeRDP Update Fixes Six RHEL 8 Vulnerabilities
Quick Answer
Red Hat published RHSA-2026:76747 for Red Hat Enterprise Linux 8 FreeRDP client and library packages. Match entitled deployments to the exact advisory relationships, apply freerdp 2.11.7-14.el8_10, validate dependent operations, and preserve evidence.
Validate FreeRDP Scope And Apply The Red Hat Fix
What to do now: Inventory Red Hat Enterprise Linux 8 FreeRDP client and library packages, confirm the exact entitled branch and installed build or digest, apply the advisory-listed content, validate representative services, and document exceptions.
Last verified: 2026-10-06 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.
Scope And Authority
| Product scope | Red Hat Enterprise Linux 8 FreeRDP client and library packages |
|---|---|
| Advisory | RHSA-2026:76747 |
| CVEs | CVE-2026-91953, CVE-2026-91954, CVE-2026-91956, CVE-2026-91959, CVE-2026-91963, CVE-2026-91964 |
| Authoritative release date | 2026-10-06 15:16:12 UTC |
| Authority revision date | 2026-10-06 15:16:46 UTC |
| Affected versions | The supported Red Hat Enterprise Linux 8 FreeRDP client and library packages builds identified as affected by the advisory product-status relationships. |
| Fixed version | freerdp 2.11.7-14.el8_10 |
| CVSS base score | 6.5 / 8.8 (CVSS v3.1) |
| CVSS severity | Medium to High |
| Exploitation status | Not stated by the authority; no exploitation claim is inferred. |
What Changed
Red Hat released FreeRDP 2.11.7-14 packages for six vulnerabilities on the advisory-listed RHEL 8 channels.
What To Validate Now
- Inventory. Locate Red Hat Enterprise Linux 8 FreeRDP client and library packages; record the installed build or digest, repository and entitlement, owner, exposure, dependencies, and maintenance group.
- Establish applicability. Compare each deployment with the product and fixed-status relationships in RHSA-2026:76747. Do not infer applicability from a component name or CVSS rating alone.
- Remediate. Apply freerdp 2.11.7-14.el8_10 from the supported Red Hat channel for the exact product branch or architecture.
- Validate. Confirm the resulting package version or immutable digest, exercise representative FreeRDP services and recovery paths, monitor for regressions, and record the result.
- Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.
Operational Cautions
Validate representative RDP authentication, gateway, certificate, graphics, clipboard, device-redirection, and dependent application workflows. Preserve pre-change versions or digests, logs, installation output, validation evidence, and rollback decisions.
Evidence To Retain
- Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
- UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
- Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.
Related TechGeeks Resources
Authoritative References
Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

