
Software
there's an unauthenticated 9.8 in Windows RDP. we've seen how this movie ends — patch before the sequel
CVE-2026-56190 lets an attacker run code on a Windows machine over Remote Desktop with no login and no clicks. It's the same profile as BlueKeep — the RDP bug that became a worm. It isn't exploited yet. 'Yet' is the word to act on.
Priya Nair · 2d ago · 7 min