Jul 2026: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-56171 Published on July 17, 2026
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
Weakness Type
What is a Privacy violation Vulnerability?
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.
CVE-2026-56171 has been classified to as a Privacy violation vulnerability or weakness.
Products Associated with CVE-2026-56171
stack.watch emails you whenever new vulnerabilities are published in Microsoft Windows Admin Center or Microsoft Remote Desktop Web Client. Just hit a watch button to start following.
Affected Versions
Microsoft Remote Desktop Web Client:- Version 2.0.0.0 and below 2.1.65.2 is affected.
- Version 1809.0 and below 2.7.4 is affected.