Remote Desktop Client Remote Code Execution Vulnerability

Date Jul 14, 2026
Type Patch Tuesday
Signal Critical vendor advisory
Vendor / Product Microsoft ยท Remote Desktop Client
CVE CVE-2026-54990
Critical vendor advisory CVE-2026-54990

Summary

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Published in July 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely.

Why it matters

Microsoft published this item through its Security Update Guide, making it part of Patch Tuesday triage for affected Windows, cloud, or application estates.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-54990. Confirm whether Remote Desktop Client is deployed, then apply the current security update or documented mitigation. CVSS score: 9.8.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.