CVE-2026-32157High· 8.8▾ TwilightUse after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.8%
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
remote_desktop_client < 2.0.1070.0windows_10_1607 < 10.0.14393.9060windows_10_1809 < 10.0.17763.8644windows_10_21h2 < 10.0.19044.7184windows_10_22h2 < 10.0.19045.7184windows_11_23h2 < 10.0.22631.6936windows_11_24h2 < 10.0.26100.8246windows_11_25h2 < 10.0.26200.8246windows_11_26h1 < 10.0.28000.1836windows_server_2012windows_server_2012 = r2windows_server_2016 < 10.0.14393.9060windows_server_2019 < 10.0.17763.8644windows_server_2022 < 10.0.20348.5020windows_server_2022_23h2 < 10.0.25398.2274windows_server_2025 < 10.0.26100.32690Upgrade past the affected range:
remote_desktop_client 2.0.1070.0windows_10_1607 10.0.14393.9060windows_10_1809 10.0.17763.8644windows_10_21h2 10.0.19044.7184windows_10_22h2 10.0.19045.7184windows_11_23h2 10.0.22631.6936windows_11_24h2 10.0.26100.8246windows_11_25h2 10.0.26200.8246windows_11_26h1 10.0.28000.1836windows_server_2016 10.0.14393.9060windows_server_2019 10.0.17763.8644windows_server_2022 10.0.20348.5020windows_server_2022_23h2 10.0.25398.2274windows_server_2025 10.0.26100.32690Connected by shared product, vendor, weakness, or advisory.
CVE-2021-26411High· 8.8Internet Explorer Memory Corruption Vulnerability
CVE-2021-34486High· 7.8Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2026-88097High· 8.1Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.
CVE-2026-85893High· 8.8Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-70341High· 8.5Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
CVE-2026-85360High· 7.0Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.