Sep 2026: Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-78463 Published on September 8, 2026

Remote Desktop Client Remote Code Execution Vulnerability
Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Vendor Advisory NVD

Weakness Type

What is a Code Injection Vulnerability?

The software constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

CVE-2026-78463 has been classified to as a Code Injection vulnerability or weakness.


Products Associated with CVE-2026-78463

Want to know whenever a new CVE is published for Microsoft Remote Desktop? stack.watch will email you.

 

Affected Versions

Microsoft Remote Desktop client for Windows Desktop: