Jul 2026: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-56171 Published on July 17, 2026

Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.

Vendor Advisory NVD

Weakness Type

What is a Privacy violation Vulnerability?

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

CVE-2026-56171 has been classified to as a Privacy violation vulnerability or weakness.


Products Associated with CVE-2026-56171

stack.watch emails you whenever new vulnerabilities are published in Microsoft Windows Admin Center or Microsoft Remote Desktop Web Client. Just hit a watch button to start following.

 
 

Affected Versions

Microsoft Remote Desktop Web Client: Microsoft Windows Admin Center: