Red Hat Updates FreeRDP for CVE-2026-55193 Across RHEL 8.4 and 8.6 Extended Branches
Quick Answer
Red Hat published RHSA-2026:73026 and RHSA-2026:73027 for FreeRDP on entitled RHEL 8.4 and 8.6 AUS or EUS Extension streams. Inventory only entitled systems in the listed branches, apply freerdp-2:2.2.0-14.el8_4.4.src / freerdp-2:2.2.0-7.el8_6.13.src, validate remote-desktop and TS Gateway client workflows, and retain entitlement, package, and change evidence.
Confirm Scope And Apply The Supported Fix
What to do now: Identify entitled systems in the exact advisory branches, confirm the installed source package, apply freerdp-2:2.2.0-14.el8_4.4.src / freerdp-2:2.2.0-7.el8_6.13.src, validate remote-desktop and TS Gateway client workflows, and preserve entitlement, package-manager, service, and test evidence.
Last verified: 2026-09-29 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.
Scope And Authority
| Product scope | FreeRDP on entitled RHEL 8.4 and 8.6 AUS or EUS Extension streams |
|---|---|
| Advisory | RHSA-2026:73026 / RHSA-2026:73027 |
| CVE | CVE-2026-55193 |
| Authoritative release date | 2026-09-29 07:06:11 UTC |
| Authority revision date | 2026-09-29 10:15:46 UTC |
| Affected versions | The RHEL 8.4 and 8.6 AppStream AUS or EUS Extension branches identified by RHSA-2026:73026 and RHSA-2026:73027 before their advisory-listed fixed builds. |
| Fixed version | freerdp-2:2.2.0-14.el8_4.4.src / freerdp-2:2.2.0-7.el8_6.13.src |
| CVSS base score | 8.8 (official CVSS v3.1) |
| CVSS severity | High |
| Exploitation status | Not stated by the authority; no exploitation claim is inferred. |
What Changed
Red Hat corrected a FreeRDP TS Gateway heap-buffer overflow that can crash a client and may permit arbitrary code execution when a client processes a malicious gateway response fragment.
What To Validate Now
- Inventory. Locate entitled systems using FreeRDP on entitled RHEL 8.4 and 8.6 AUS or EUS Extension streams; record the RHEL minor stream, repository entitlement, source package, architecture, owner, and dependent applications.
- Establish applicability. Match each system to RHSA-2026:73026 and RHSA-2026:73027. The RHEL 8.4 and 8.6 AppStream AUS or EUS Extension branches identified by RHSA-2026:73026 and RHSA-2026:73027 before their advisory-listed fixed builds. Do not generalize this branch-specific fix to other RHEL streams.
- Remediate. Apply freerdp-2:2.2.0-14.el8_4.4.src / freerdp-2:2.2.0-7.el8_6.13.src through the matching entitled Red Hat repository and normal change control; Red Hat states that no qualifying workaround is available.
- Validate. Confirm the resulting package and repository branch, exercise representative remote-desktop and TS Gateway client workflows, monitor for regressions, and document exceptions or rollback.
- Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.
Operational Cautions
These are branch-specific extended-support fixes. Confirm entitlement and repository configuration before deployment, preserve configuration and rollback options, and do not treat the CVSS score as evidence of exploitation.
Evidence To Retain
- Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
- UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
- Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.
Related TechGeeks Resources
Authoritative References
Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

