CVE-2026-58626
Microsoft · Published July 14, 2026
8.8
CVSS v3.1
HIGHPatch availableGet patch
Description
Windows Remote Desktop Services Remote Code Execution Vulnerability. Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
Affected Products
- Windows Server 2022
- Windows 10 Version 21H2 for 32-bit Systems
- Windows 10 Version 21H2 for ARM64-based Systems
- Windows 10 Version 21H2 for x64-based Systems
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C