CVE-2026-56171: Microsoft Remote Desktop Web Client
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
Affected products
- Microsoft Remote Desktop Web Client: before 2.1.65.2 (fixed in 2.1.65.2)
- Microsoft Windows Admin Center: before 2606 (fixed in 2606)
Published 2026-07-17. Last modified 2026-07-22.