CVE-2026-58598
An attacker can exploit multiple vulnerabilities in Microsoft Windows Backup Service, Microsoft Windows Admin Center, and Microsoft Windows Remote Desktop Web Client to disclose information and gain elevated privileges.
CSIRTS triage
- What
- An attacker can exploit multiple vulnerabilities in Microsoft Windows Backup Service, Microsoft Windows Admin Center, and Microsoft Windows Remote Desktop Web Client to disclose information and gain elevated privileges.
- Who is affected
- Users of Microsoft Windows services are affected.
- Urgency
- Remediation is medium due to the potential for information disclosure and privilege escalation.
- Action
- Apply the latest updates for Microsoft Windows.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-58598
Get an email if CVE-2026-58598 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
Advisory coverage (4)
- medium[NEW] [medium] Microsoft Windows: Multiple Vulnerabilitiescert-bund · 2026-07-20
- unknownMultiple vulnerabilities in Microsoft Windows (July 17, 2026)cert-fr-avis · 2026-07-17
- highCVE-2026-58598: Concurrent execution using shared resource with improper synchronization ('race condition') in…nvd · 2026-07-16
- highCVE-2026-58598: Windows Backup Service Elevation of Privilege Vulnerabilitymsrc · 2026-07-14
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-58598)