Junglewise Threat Intelligence

CVE-2026-57098: Microsoft Windows RDP Client cryptographic signature verification bypass

CVE-2026-57098 · Severity: high · CVSS 7.5 · Published 2026-09-08

Technologies: Microsoft Remote Desktop Client. Vendors: Microsoft.

Executive brief

The Windows RDP Client contains a flaw in its cryptographic signature verification mechanism that could allow an attacker to forge or bypass authentication checks. An unauthorized attacker with network access could exploit this to gain unauthorized access to RDP sessions or intercept sensitive data transmitted over the network connection.

Technical details

The vulnerability exists in the Windows RDP Client's improper verification of cryptographic signatures, which are used to authenticate the legitimacy of RDP protocol messages. The flaw allows an attacker on the network to forge or manipulate signed RDP messages without proper validation, potentially leading to authentication bypass or man-in-the-middle attacks. This is a network-reachable vulnerability that requires the attacker to be positioned to intercept or modify RDP traffic. An attacker can exploit this to disclose information or establish unauthorized RDP sessions.

Affected products

  • Microsoft Windows RDP Client

Timeline

  • 2026-09-08: disclosed

References

Related threats