CVE-2026-26151Patch(microsoft / windows_10_1607)

MEDIUMCVSS 7.1 · HIGH

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spoofing over a network.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-357

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-04-17)
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2012windows_server_2016

2 versions affected across 14 products

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-04-14: 2Mentions · 2026-04-15: 1Mentions · 2026-04-16: 1Mentions · 2026-04-17: 3Active Exploitation · 2026-04-14: 1Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-17: 204-1404-1504-1604-17
Signal classification4 categories
Patch
342.9%
Disclosure
228.6%
Active Exploitation
114.3%
General
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-142
Active Exploitation1Patch1
2026-04-151
Patch1
2026-04-161
Patch1
2026-04-173
Disclosure2General1
Full discourse7 posts
  • Iván Salado@isaladolopez
    General

    @wisepds @Microsoft Es cierto que es una lata, pero también es cierto que lo han hecho para tapar un CVE-2026-26151 de alto riesgo. Al final, es por seguridad; aunque la seguridad no siempre va acompañada de comodidad, por desgracia.

    Post summary

    The tweet notes that a CVE-2026-26151 of high risk has been addressed, but provides no concrete details or evidence of exploitation, patching, or a PoC.

    10000479
    470 followersView on X
  • Deskmodder@deskmodder
    Patch

    Remote Desktop mit neuen Sicherheitsmaßnahmen unter Windows 10, 11 und Server Gestern zum Patchday hat Microsoft eine Sicherheitslücke (CVE-2026-26151), die den Remote Desktop be... https://www.deskmodder.de/blog/2026/04/15/remote-desktop-mit-neuen-sicherheitsmassnahmen-unter-windows-10-11-und-server/

    Post summary

    Microsoft disclosed CVE-2026-26151 affecting Remote Desktop and announced a patch.

    0001077
    102 followersView on X
  • kawn@kawn2020
    Active Exploitation

    #windowsupdate #microsoft ●悪用可能性 -悪用の事実を確認済み:1 件 ・CVE-2026-32201 6.5 Microsoft Office SharePoint -悪用される可能性が高い:19 件 ・CVE-2026-0390  6.7 Windows ブート ローダー ・CVE-2026-26151 7.1 Windows リモート デスクトップ … https://x.com/kawn2020/status/2044199643110949331

    Post summary

    The tweet confirms active exploitation of CVE‑2026‑32201 and references other high‑risk CVEs, but lacks technical or remediation details.

    10000366
    85 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-26151 Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spoofing over a network. https://www.cve.org/CVERecord?id=CVE-2026-26151 ----- Traducción: CVE-2026-26151 Advertencia insuficiente de la… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-26151, highlighting a UI warning deficiency in Windows Remote Desktop that permits spoofing, but provides no PoC, exploit, patch, or active exploitation details.

    0000039
    71 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26151 Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spoofing over a network. https://www.cve.org/CVERecord?id=CVE-2026-26151

    Post summary

    The post announces CVE-2026-26151, describing an insufficient UI warning in Windows Remote Desktop that permits network spoofing.

    00000198
    57.2K followersView on X
  • Virtual Cable@VirtualCable_
    Patch

    🔐 Microsoft introduce mejoras de seguridad en RDP frente a la vulnerabilidad CVE-2026-26151 ⚠️ Nuevos avisos, control de recursos locales y mayor protección ante archivos .RDP maliciosos 🤝 Si eres partner o cliente de #VirtualCable y tienes dudas: support@udsenterprise.com https://t.co/Xr5QLrfw0h

    Post summary

    Microsoft has released RDP security enhancements for CVE-2026-26151, offering improved protection and local resource controls, though no proof‑of‑concept or active exploitation details are provided.

    0000044
    628 followersView on X
  • Red Hornet Intel@RedHornet_Intel
    Patch

    CVE-2026-26151 | Microsoft Windows 10 Version 1607 | Vulnerability Description Insufficient UI warning in Windows Remote Desktop enables unauth attackers to perform spoofing over a network by misleading users into dangerous operations, compromising session integrity in Windows 10 Version 1607. Severity: High Exploitation: Unknown Public PoC: Unknown Patch Available: Yes Affected Product: Microsoft Windows 10 Version 1607 Affected Version: >= 10.0.14393.0 and < 10.0.14393.9060 Sources Vendor: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26151

    Post summary

    CVE-2026-26151 exposes a high‑severity UI warning flaw in Windows 10 Version 1607 that could allow unauthorized session spoofing; Microsoft has released a patch, but no public PoC or evidence of active exploitation has been reported.

    0000060
    8 followersView on X
CPE platform detail25 entries

25 of 25 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more