CVE-2026-56171
published 2026-07-17CVE-2026-56171: Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.48%
38.7th percentile
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | remote_desktop_web_client | < 2.1.65.2 | 2.1.65.2 |
| microsoft | remote_desktop_web_client | >= 2.0.0.0 < 2.1.65.2 | 2.1.65.2 |
| microsoft | windows_admin_center | < 2606 | 2606 |
| microsoft | windows_admin_center | >= 1809.0 < 2.7.4 | 2.7.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
ghsa_unreviewed·2026-07-18
CVE-2026-56171 [HIGH] CWE-359 Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
VulDB
Microsoft Windows RDP information disclosure
vuldb·2026-07-17·CVSS 7.1
CVE-2026-56171 [HIGH] Microsoft Windows RDP information disclosure
A vulnerability described as problematic has been identified in Microsoft Windows. Impacted is an unknown function of the component RDP. Such manipulation leads to information disclosure.
This vulnerability is referenced as CVE-2026-56171. It is possible to launch the attack remotely. No exploit is available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-17
Published