๐Ÿ” CVE Alert

CVE-2026-21533

HIGH 7.8 โš ๏ธ CISA KEV

Windows Remote Desktop Services Elevation of Privilege Vulnerability

CVSS Score
7.8
EPSS Score
22.7%
EPSS Percentile
96th

Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

Vendor microsoft
Product windows 10 version 1607
Ecosystems
Industries
TechnologyEnterprise
Published Feb 10, 2026
Last Updated Apr 10, 2026
โš ๏ธ Actively Exploited โ€” Act Now

Get instant alerts for microsoft windows 10 version 1607

This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2026-21533.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Microsoft / Windows 10 Version 1607
10.0.14393.0 < 10.0.14393.8868
Microsoft / Windows 10 Version 1809
10.0.17763.0 < 10.0.17763.8389
Microsoft / Windows 10 Version 21H2
10.0.19044.0 < 10.0.19044.6937
Microsoft / Windows 10 Version 22H2
10.0.19045.0 < 10.0.19045.6937
Microsoft / Windows 11 version 22H3
10.0.22631.0 < 10.0.22631.6649
Microsoft / Windows 11 Version 23H2
10.0.22631.0 < 10.0.22631.6649
Microsoft / Windows 11 Version 24H2
10.0.26100.0 < 10.0.26100.7840
Microsoft / Windows 11 Version 25H2
10.0.26200.0 < 10.0.26200.7840
Microsoft / Windows 11 version 26H1
10.0.28000.0 < 10.0.28000.1575
Microsoft / Windows 11 Version 26H1
10.0.28000.0 < 10.0.28000.1575
Microsoft / Windows Server 2012
6.2.9200.0 < 6.2.9200.25923
Microsoft / Windows Server 2012 (Server Core installation)
6.2.9200.0 < 6.2.9200.25923
Microsoft / Windows Server 2012 R2
6.3.9600.0 < 6.3.9600.23022
Microsoft / Windows Server 2012 R2 (Server Core installation)
6.3.9600.0 < 6.3.9600.23022
Microsoft / Windows Server 2016
10.0.14393.0 < 10.0.14393.8868
Microsoft / Windows Server 2016 (Server Core installation)
10.0.14393.0 < 10.0.14393.8868
Microsoft / Windows Server 2019
10.0.17763.0 < 10.0.17763.8389
Microsoft / Windows Server 2019 (Server Core installation)
10.0.17763.0 < 10.0.17763.8389
Microsoft / Windows Server 2022
10.0.20348.0 < 10.0.20348.4773
Microsoft / Windows Server 2022, 23H2 Edition (Server Core installation)
10.0.25398.0 < 10.0.25398.2149
Microsoft / Windows Server 2025
10.0.26100.0 < 10.0.26100.32370
Microsoft / Windows Server 2025 (Server Core installation)
10.0.26100.0 < 10.0.26100.32370

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
msrc.microsoft.com: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21533 cisa.gov: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21533 vicarius.io: https://www.vicarius.io/vsociety/posts/cve-2026-21533-detection-script-privilege-escalation-vulnerability-in-windows-remote-desktop vicarius.io: https://www.vicarius.io/vsociety/posts/cve-2026-21533-mitigation-script-privilege-escalation-vulnerability-in-windows-remote-desktop