CVE-2026-23660Disclosure(microsoft / windows_admin_center)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft windows_admin_center systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_admin_center

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 1 mentions (2026-03-10); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
windows_admin_center

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Mentions · 2026-03-16: 1Mentions · 2026-03-17: 1Patch / Workaround · 2026-03-16: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-17: 103-1003-1103-1603-17
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-101
Disclosure1
2026-03-111
Disclosure1
2026-03-161
Patch1
2026-03-171
Disclosure1
Full discourse4 posts
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Microsoft Windows Admin Center in Azure Portal (CVE-2026-23660) https://vuldb.com/?id.349981

    Post summary

    A newly discovered CVE-2026-23660 affecting Microsoft Windows Admin Center in Azure Portal has been announced, with no further technical or mitigation details provided.

    0000168
    2.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23660 Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally. https://www.cve.org/CVERecord?id=CVE-2026-23660

    Post summary

    The text announces CVE‑2026‑23660 as an improper access control flaw in Azure Portal's Windows Admin Center that enables local privilege escalation by authorized users.

    00000159
    56.8K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Patch

    🚨 #CVE-2026-23660: #Azure-Bound #Windows Admin Center Flaw Opens Door to Privilege Escalation—Patch Now + Video https://undercodetesting.com/cve-2026-23660-azure-bound-windows-admin-center-flaw-opens-door-to-privilege-escalation-patch-now-video/ Educational Purposes!

    Post summary

    The tweet announces CVE‑2026‑23660, a privilege‑escalation vulnerability in Azure‑bound Windows Admin Center, and urges users to apply the patch and watch the accompanying video.

    0000012
    402 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-23660 - Microsoft - Windows Admin Center in Azure Portal - https://www.redpacketsecurity.com/cve-alert-cve-2026-23660-microsoft-windows-admin-center-in-azure-portal/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-23660 #microsoft #windows-admin-center-in-azure-portal

    Post summary

    The tweet promotes a CVE alert for CVE-2026-23660, pointing to a link for the CVE report, without disclosing exploitation details or mitigation information.

    0000079
    3.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftwindows_admin_center-azure-

Explore more