Sep 2026: Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-78463 Published on September 8, 2026
Remote Desktop Client Remote Code Execution Vulnerability
Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Weakness Type
What is a Code Injection Vulnerability?
The software constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CVE-2026-78463 has been classified to as a Code Injection vulnerability or weakness.
Products Associated with CVE-2026-78463
Want to know whenever a new CVE is published for Microsoft Remote Desktop? stack.watch will email you.
Affected Versions
Microsoft Remote Desktop client for Windows Desktop:- Version 1.2.0.0 and below 1.2.7279.0 is affected.