logo

Microsoft Patches CVE-2026-26119 Privilege Escalation in Windows Admin Center

ID: ffaa7ffd-6a37-5f5e-a5c6-834a967e6e5a

STIX ID: report--ffaa7ffd-6a37-5f5e-a5c6-834a967e6e5a

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-02-19

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Microsoft disclosed and patched a high-severity privilege-escalation vulnerability (CVE-2026-26119, CVSS 8.8) in Windows Admin Center that could let an attacker gain the rights of the user running the application and — under some conditions described by the researcher — lead to full domain compromise; the issue was credited to Semperis researcher Andrea Pierini and fixed in Windows Admin Center version 2511, and Microsoft labeled the flaw 'Exploitation More Likely' though no active exploitation has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.