CVE-2026-26151CWE-357

Remote Desktop Spoofing Vulnerability

High · published April 14, 2026

CVSS v3.1
7.1
EPSS
1%
Percentile
55.2
In the wild
Unconfirmed
What it is

Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spoofing over a network.

The record
Technical detail
CVSS v3.1
7.1 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C
CVSS v4.0
Not supplied
EPSS
0.00830 · 55.2th percentile
Weakness
CWE-357 · Insufficient UI Warning of Dangerous Operations
Published
2026-04-14T16:56Z
EPSS history
Timeline
  • 14 APR 16:56Z
    Remote Desktop Spoofing Vulnerability
    cvelistv5