
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-56171 is an information disclosure vulnerability classified as "Exposure of Private Personal Information to an Unauthorized Actor" (CWE-359) affecting Microsoft's Windows Remote Desktop Protocol (RDP) components. It was disclosed on July 16, 2026, via Microsoft's Security Response Center and affects Remote Desktop Web Client versions from 2.0.0.0 up to (but not including) 2.1.65.2, and Windows Admin Center versions from 1809.0 up to (but not including) 2.7.4. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) per NVD scoring, and 7.1 (High) per ENISA/GitHub Advisory scoring (Microsoft MSRC, GitHub Advisory).
The root cause is improper protection of private personal information within Windows RDP-related components (CWE-359), allowing an unauthorized network-based attacker to access data they should not be able to view. The attack vector is network-based with low attack complexity and no privileges required; however, the GitHub Advisory scoring notes that user interaction is required, suggesting the disclosure may be triggered through a user's interaction with a malicious or crafted session/link. No public technical write-ups or proof-of-concept code have been identified at this time (Microsoft MSRC, GitHub Advisory).
Successful exploitation results in unauthorized disclosure of private personal information transmitted or processed through Windows Remote Desktop Web Client or Windows Admin Center, with a high confidentiality impact and no integrity or availability impact. An attacker operating over the network could intercept or access sensitive user data — potentially including credentials, session tokens, or personal identifiers — without requiring authentication. There is no evidence of lateral movement capability or availability disruption associated with this vulnerability (Microsoft MSRC, GitHub Advisory).
As of the time of reporting, there is no known public exploit code, active in-the-wild exploitation, or threat actor attribution associated with CVE-2026-56171. The EPSS score is approximately 0.66% (per Feedly) to 0.48% (per GitHub Advisory), placing it in the lower-to-mid range of exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and SSVC assessment indicates exploitation is currently "none" and the attack is not fully automatable (Microsoft MSRC, GitHub Advisory).
Microsoft has released patched versions addressing this vulnerability: Remote Desktop Web Client 2.1.65.2 and Windows Admin Center 2.7.4 (build 2606). Organizations should update to these versions or later as the primary remediation. No specific configuration-based workarounds have been publicly documented; restricting network access to Remote Desktop Web Client and Windows Admin Center interfaces to trusted networks can reduce exposure while patching is pending (Microsoft MSRC).
Security researcher Will Dormann (@wdormann) noted the vulnerability on Infosec.Exchange shortly after disclosure, though no detailed technical commentary was published. Automated vulnerability tracking services (VulnDB, CVEFeed, Kaspersky Threat Intelligence) indexed the CVE within 24–48 hours of disclosure. No significant media coverage or broader community debate has been identified beyond standard vulnerability aggregation (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."