tls_match_hostname of the file libfreerdp/crypto/tls.c of the component TLS Hostname Matcher. The manipulation leads to improper certificate validation.
This vulnerability is documented as CVE-2026-67293. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2026-67293 | FreeRDP up to 3.28.0 TLS Hostname Matcher libfreerdp/crypto/tls.c tls_match_hostname certificate validation (EUVD-2026-51860 / Nessus ID 331619)
Reagiere als Erste:r — dein Feedback zählt!
A vulnerability has been found in FreeRDP up to 3.28.0 and classified as problematic. Affected is the function
SOCIAL SHARE CARD GENERATOR