there's an unauthenticated 9.8 in Windows RDP. we've seen how this movie ends — patch before the sequel

CVE-2026-56190 lets an attacker run code on a Windows machine over Remote Desktop with no login and no clicks. It's the same profile as BlueKeep —…

Aliteq
Priya Nair · Software & Systems Editor

What you need to know

The flaw: a use-of-uninitialized-resource bug (CWE-908) in Windows RDP that allows unauthenticated remote code execution over the network.

What you need to know

Attack profile: network vector, low complexity, no privileges, no user interaction (AV:N/AC:L/PR:N/UI:N) — the wormable class.

What you need to know

Affected: Windows 10, Windows 11, and Windows Server 2012 through 2025, 32- and 64-bit.

What you need to know

Not yet exploited (per CISA as of mid-July) — but public exploit development for RDP 9.8s tends to be fast.

What you need to know

Fix: the July 2026 security update. Also: don't expose RDP to the internet, and turn on Network Level Authentication.

Patch this one before it's exploited, not after

The temptation with a not-yet-exploited bug is to deprioritise it behind the ones already being used. For a wormable-class RDP 9.8, resist that. BlueKeep went from patch to mass-exploitation and…

Aliteq

Read the full story

there's an unauthenticated 9.8 in Windows RDP. we've seen how this movie ends — patch before the sequel

Read the full story on Aliteq