Impact
The vulnerability is a use‑after‑free flaw in Windows Remote Desktop Services that enables an attacker who has authorized access to the service to send crafted network packets that cause the server to execute arbitrary code in the context of the Remote Desktop Services process. The effect is full system compromise, yielding complete confidentiality, integrity, and availability loss. The weakness is identified as CWE‑416.
Affected Systems
Microsoft Windows 10 versions 21H2 and 22H2, Windows 11 versions 24H2, 25H2, and 26H1, Windows Server 2022, Windows Server 2025 including its Server Core installation are affected. Users of any of these operating system releases should verify whether the Microsoft update that patches CVE‑2026‑58626 has been applied.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity impact. The EPSS score is below 1 %, implying a currently low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker would need authorized access to a device that has Remote Desktop Services enabled; the attack can be launched over the network by sending a specially crafted packet. No publicly available exploit code is referenced in the CVE data.
OpenCVE Enrichment