Junglewise Threat Intelligence

CVE-2026-54126: Microsoft Windows RDP out-of-bounds read information disclosure

CVE-2026-54126 · Severity: medium · CVSS 6.5 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Remote Desktop Protocol (RDP), which is commonly used for remote access to computers and servers. An attacker could exploit this flaw to gain unauthorized access to sensitive information stored in the system's memory. While the attack can be initiated over a network, it requires a user to perform a specific action, such as clicking a link or opening a malicious file, to be successful.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the Microsoft Windows Remote Desktop Protocol (RDP) implementation. The flaw allows a remote, unauthenticated attacker to disclose sensitive information by triggering a read operation outside of intended memory buffers. Although the attack vector is network-based, the CVSS metric indicates that user interaction is required for successful exploitation. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server 2012. Microsoft has released security updates to address this issue across the affected platforms.

Affected products

  • Microsoft Windows 10 Versions 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 Versions 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 All editions including Server Core

Timeline

  • 2026-07-14: advisory: Initial disclosure by Microsoft and NVD publication
  • 2026-07-14: patched: Security updates made available via Microsoft Security Update Guide

References

Related threats