logo

One-Click RCE in Azure Windows Admin Center Lets Attackers Execute Arbitrary Commands

ID: 17bf1d5c-b280-5797-954d-4e421b0079c9

STIX ID: report--17bf1d5c-b280-5797-954d-4e421b0079c9

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-04-16

Date Updated: 2026-04-16

Author: AnuPriya

...
...

**Executive summary:** A critical chained vulnerability (CVE-2026-32196) in Microsoft Windows Admin Center allows attackers to use a crafted gateway URL to trigger response-based XSS and control-flow hijacking, leading to unauthenticated one-click PowerShell RCE on on-prem WAC instances and theft of Azure access/refresh tokens from browser local storage; Azure-hosted WAC was remediated server-side while on-prem customers must apply the Microsoft update, restrict access, and audit tokens and gateway exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.