CVE-2026-56171: Microsoft Remote Desktop Web Client

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.

Affected products

  • Microsoft Remote Desktop Web Client: before 2.1.65.2 (fixed in 2.1.65.2)
  • Microsoft Windows Admin Center: before 2606 (fixed in 2606)

Published 2026-07-17. Last modified 2026-07-22.