logo

Microsoft: Critical Windows Admin Center Flaw Allows Privilege Escalation

ID: 801e6022-3dee-5da8-b4d0-0e6e19ec0569

STIX ID: report--801e6022-3dee-5da8-b4d0-0e6e19ec0569

Feed Name: TechRepublic Security

Threat Score
70/100

Date Published: 2026-02-19

Date Updated: 2026-04-23

Author: Ken Underhill

...
...

A critical authentication flaw (CVE-2026-26119, CVSS 8.8) in Windows Admin Center v2.6.4 can let an authorized low-privilege user elevate privileges across enterprise-managed systems, potentially granting administrative control over multiple servers; Microsoft has not reported active exploitation, and recommended mitigations include patching, enforcing least privilege, enabling MFA, restricting network exposure, and enhanced monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.