A vulnerability classified as problematic was found in FreeRDP up to 3.28.0. Affected is the function update_process_glyph_fragments/glyph_cache_fragment_put of the file libfreerdp/cache/glyph.c of the component Glyph Cache. Executing a manipulation can lead to out-of-bounds read.

This vulnerability is tracked as CVE-2026-67291. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is advised.