This CVE has been withdrawn by MITRE
MITRE marked CVE-2026-72746 as REJECTED on . There is no longer a valid blast radius to assess. Any historical package or vendor data shown below is preserved for audit reference only.
Reason given by MITRE
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-73241.
CVE-2026-72746 Blast Radius
✕ WITHDRAWN — HISTORICAL DATAFreeRDP before 3.30.0 contains a server-side authentication bypass in the RDSTLS handshake. When a server is configured with RdstlsSecurity = TRUE, th…