{
  "title": "CVE of the day — CVE-2026-64620 (CVSS 9,8, criticism)",
  "title_variants": [
    {
      "id": "v0",
      "title": "CVE of the day — CVE-2026-64620 (CVSS 9,8, criticism)"
    },
    {
      "id": "v1",
      "title": "CVE-2026-64620: critical vulnerability, CVSS 9,8/10, type CWE-122, exploitable remotely,"
    }
  ],
  "description": "CVE-2026-64620: critical vulnerability, CVSS 9,8/10, type CWE-122, exploitable remotely, without privileges, without user interaction. FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto rsa common() (libfreerdp/crypto/crypto.c). The function writes the..",
  "keywords": [
    "c",
    "cve-2026-64620",
    "vulnerability",
    "critical vulnerability",
    "cwe-122",
    "cvs",
    "cybersecurity",
    "cybersecurity",
    "♪",
    "security update"
  ],
  "scenes": [
    {
      "title": "CVE-2026- 64620",
      "subtitle": "CVSS 9,8",
      "text": "CVE-2026-64620: Critical gravity, CVSS score 9,8 out of 10 according to the National Vulnerability Database."
    },
    {
      "title": "CWE-122",
      "subtitle": "CWE-122 · CVSS v3.1",
      "text": "FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto rsa common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the caller's output buffer.."
    },
    {
      "title": "EXPOSURE AND MITIGATION",
      "subtitle": "remotely exploitable, without privileges, without user interaction",
      "text": "Remotely exploitable Vulnerability, without privileges, without user interaction. Apply the update of the supplier promptly and consult the official notice on NVD."
    }
  ],
  "publication_date": "2026-07-22T01:03:02.225Z",
  "duration": 20,
  "topic": "cve",
  "lang": "en",
  "translation_group": "cve-2026-07-22",
  "poster": "cve-2026-07-22-en.jpg",
  "preview": "cve-2026-07-22-en.gif",
  "og_card": "cve-2026-07-22-en.og.jpg",
  "audiogram": "cve-2026-07-22-en.audiogram.mp4",
  "captions": "cve-2026-07-22-en.vtt",
  "generation": {
    "procedural": true,
    "ai_generated": [
      "background",
      "voice"
    ],
    "real_data_source": "official public API",
    "filmed_real_event": false,
    "disclosure": "Procedurally generated from real public-source data; abstract AI-generated backgrounds; synthetic (TTS) voice. No real event is filmed or altered."
  },
  "transcript_text": "CVE-2026-64620: Critical gravity, CVSS score 9,8 out of 10 according to the National Vulnerability Database. FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto rsa common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the caller's output buffer.. Remotely exploitable Vulnerability, without privileges, without user interaction. Apply the update of the supplier promptly and consult the official notice on NVD.",
  "transcript": [
    {
      "start": 0,
      "end": 6.667,
      "text": "CVE-2026-64620: Critical gravity, CVSS score 9,8 out of 10 according to the National Vulnerability Database."
    },
    {
      "start": 6.667,
      "end": 13.333,
      "text": "FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto rsa common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the caller's output buffer.."
    },
    {
      "start": 13.333,
      "end": 20,
      "text": "Remotely exploitable Vulnerability, without privileges, without user interaction. Apply the update of the supplier promptly and consult the official notice on NVD."
    }
  ]
}