CVE-2026-56171
Windows Admin Center vulnerability analysis and mitigation

Overview

CVE-2026-56171 is an information disclosure vulnerability classified as "Exposure of Private Personal Information to an Unauthorized Actor" (CWE-359) affecting Microsoft's Windows Remote Desktop Protocol (RDP) components. It was disclosed on July 16, 2026, via Microsoft's Security Response Center and affects Remote Desktop Web Client versions from 2.0.0.0 up to (but not including) 2.1.65.2, and Windows Admin Center versions from 1809.0 up to (but not including) 2.7.4. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) per NVD scoring, and 7.1 (High) per ENISA/GitHub Advisory scoring (Microsoft MSRC, GitHub Advisory).

Technical details

The root cause is improper protection of private personal information within Windows RDP-related components (CWE-359), allowing an unauthorized network-based attacker to access data they should not be able to view. The attack vector is network-based with low attack complexity and no privileges required; however, the GitHub Advisory scoring notes that user interaction is required, suggesting the disclosure may be triggered through a user's interaction with a malicious or crafted session/link. No public technical write-ups or proof-of-concept code have been identified at this time (Microsoft MSRC, GitHub Advisory).

Impact

Successful exploitation results in unauthorized disclosure of private personal information transmitted or processed through Windows Remote Desktop Web Client or Windows Admin Center, with a high confidentiality impact and no integrity or availability impact. An attacker operating over the network could intercept or access sensitive user data — potentially including credentials, session tokens, or personal identifiers — without requiring authentication. There is no evidence of lateral movement capability or availability disruption associated with this vulnerability (Microsoft MSRC, GitHub Advisory).

Exploitability

As of the time of reporting, there is no known public exploit code, active in-the-wild exploitation, or threat actor attribution associated with CVE-2026-56171. The EPSS score is approximately 0.66% (per Feedly) to 0.48% (per GitHub Advisory), placing it in the lower-to-mid range of exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and SSVC assessment indicates exploitation is currently "none" and the attack is not fully automatable (Microsoft MSRC, GitHub Advisory).

Mitigation and workarounds

Microsoft has released patched versions addressing this vulnerability: Remote Desktop Web Client 2.1.65.2 and Windows Admin Center 2.7.4 (build 2606). Organizations should update to these versions or later as the primary remediation. No specific configuration-based workarounds have been publicly documented; restricting network access to Remote Desktop Web Client and Windows Admin Center interfaces to trusted networks can reduce exposure while patching is pending (Microsoft MSRC).

Community reactions

Security researcher Will Dormann (@wdormann) noted the vulnerability on Infosec.Exchange shortly after disclosure, though no detailed technical commentary was published. Automated vulnerability tracking services (VulnDB, CVEFeed, Kaspersky Threat Intelligence) indexed the CVE within 24–48 hours of disclosure. No significant media coverage or broader community debate has been identified beyond standard vulnerability aggregation (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Windows Admin Center vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-56197HIGH8.8
  • Windows Admin Center logoWindows Admin Center
  • cpe:2.3:a:microsoft:windows_admin_center
NoYesJul 14, 2026
CVE-2026-56196HIGH8.8
  • Windows Admin Center logoWindows Admin Center
  • cpe:2.3:a:microsoft:windows_admin_center
NoYesJul 14, 2026
CVE-2026-58631HIGH7.8
  • Windows Admin Center logoWindows Admin Center
  • cpe:2.3:a:microsoft:windows_admin_center
NoYesJul 14, 2026
CVE-2026-56171HIGH7.5
  • Windows Admin Center logoWindows Admin Center
  • cpe:2.3:a:microsoft:windows_admin_center
NoYesJul 17, 2026
CVE-2026-58643MEDIUM6.1
  • Windows Admin Center logoWindows Admin Center
  • cpe:2.3:a:microsoft:windows_admin_center
NoYesJul 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management