{
  "title": "CVE of the day — CVE-2026-67289 (CVSS 9,8, critic)",
  "title_variants": [
    {
      "id": "v0",
      "title": "CVE of the day — CVE-2026-67289 (CVSS 9,8, critic)"
    },
    {
      "id": "v1",
      "title": "CVE-2026-67289: critical vulnerability, CVSS 9,8/10, type CWE-113, exploitable remotely,"
    }
  ],
  "description": "CVE-2026-67289: critical vulnerability, CVSS 9,8/10, type CWE-113, exploitable remotely, without privileges, without user interaction. FreeRDP before 3.29.0 (a versions affected <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This..",
  "keywords": [
    "c",
    "cve-2026-67289",
    "vulnerability",
    "critical vulnerability",
    "♪",
    "cvs",
    "cybersecurity",
    "cybersecurity",
    "♪",
    "security update"
  ],
  "scenes": [
    {
      "title": "CVE-2026- 67289",
      "subtitle": "CVSS 9,8",
      "text": "CVE-2026-67289: Critical gravity, CVSS score 9,8 out of 10 according to the National Vulnerability Database."
    },
    {
      "title": "CWE-113",
      "subtitle": "CWE-113 · CVSS v3.1",
      "text": "FreeRDP before 3.29.0 (a versions affected <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname.."
    },
    {
      "title": "EXPOSURE AND MITIGATION",
      "subtitle": "remotely exploitable, without privileges, without user interaction",
      "text": "Remotely exploitable Vulnerability, without privileges, without user interaction. Apply the update of the supplier promptly and consult the official notice on NVD."
    }
  ],
  "publication_date": "2026-08-03T00:51:38.188Z",
  "duration": 20,
  "topic": "cve",
  "lang": "en",
  "translation_group": "cve-2026-08-03",
  "poster": "cve-2026-08-03-en.jpg",
  "preview": "cve-2026-08-03-en.gif",
  "og_card": "cve-2026-08-03-en.og.jpg",
  "audiogram": "cve-2026-08-03-en.audiogram.mp4",
  "captions": "cve-2026-08-03-en.vtt",
  "generation": {
    "procedural": true,
    "ai_generated": [
      "background",
      "voice"
    ],
    "real_data_source": "official public API",
    "filmed_real_event": false,
    "disclosure": "Procedurally generated from real public-source data; abstract AI-generated backgrounds; synthetic (TTS) voice. No real event is filmed or altered."
  },
  "transcript_text": "CVE-2026-67289: Critical gravity, CVSS score 9,8 out of 10 according to the National Vulnerability Database. FreeRDP before 3.29.0 (a versions affected <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname.. Remotely exploitable Vulnerability, without privileges, without user interaction. Apply the update of the supplier promptly and consult the official notice on NVD.",
  "transcript": [
    {
      "start": 0,
      "end": 6.667,
      "text": "CVE-2026-67289: Critical gravity, CVSS score 9,8 out of 10 according to the National Vulnerability Database."
    },
    {
      "start": 6.667,
      "end": 13.333,
      "text": "FreeRDP before 3.29.0 (a versions affected <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname.."
    },
    {
      "start": 13.333,
      "end": 20,
      "text": "Remotely exploitable Vulnerability, without privileges, without user interaction. Apply the update of the supplier promptly and consult the official notice on NVD."
    }
  ]
}