CVE-2026-26119Patch(microsoft / windows_admin_center)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft windows_admin_center systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_admin_center

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 97 mentions across 19 observed days
  • Momentum state: declining

What's happening

  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 63 signals
  • Technical details provided in 72 signals
  • Disclosure: 27 classified signals
  • General: 7 classified signals
  • Peaked 16d ago at 32 mentions (2026-02-19); latest day: 1
  • 97 total mentions across 19 days

Affected systems

Vendors
Products
windows_admin_center

Deep dive

Activity timeline97 mentions / 19d
08162432Mentions · 2026-02-17: 3Mentions · 2026-02-18: 11Mentions · 2026-02-19: 32Mentions · 2026-02-20: 30Mentions · 2026-02-21: 2Mentions · 2026-02-24: 3Mentions · 2026-02-25: 2Mentions · 2026-02-26: 1Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-03-02: 1Mentions · 2026-03-04: 1Mentions · 2026-03-13: 1Mentions · 2026-03-23: 2Mentions · 2026-03-27: 1Mentions · 2026-04-15: 1Mentions · 2026-08-11: 1Mentions · 2026-08-12: 2Mentions · 2026-08-27: 1PoC Mentioned / Linked · 2026-08-11: 1PoC Mentioned / Linked · 2026-08-12: 1PoC Mentioned / Linked · 2026-08-27: 1Exploit Tool / Code · 2026-08-11: 1Exploit Tool / Code · 2026-08-12: 2Exploit Tool / Code · 2026-08-27: 1Patch / Workaround · 2026-02-18: 5Patch / Workaround · 2026-02-19: 24Patch / Workaround · 2026-02-20: 22Patch / Workaround · 2026-02-21: 1Patch / Workaround · 2026-02-24: 2Patch / Workaround · 2026-02-25: 2Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-02-28: 1Patch / Workaround · 2026-03-02: 1Patch / Workaround · 2026-03-04: 1Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-04-15: 1Technical Details · 2026-02-17: 3Technical Details · 2026-02-18: 7Technical Details · 2026-02-19: 25Technical Details · 2026-02-20: 19Technical Details · 2026-02-21: 2Technical Details · 2026-02-24: 3Technical Details · 2026-02-25: 1Technical Details · 2026-02-26: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-02: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-23: 2Technical Details · 2026-03-27: 1Technical Details · 2026-04-15: 1Technical Details · 2026-08-11: 1Technical Details · 2026-08-12: 202-1702-1802-1902-2002-2102-2402-2502-2602-2702-2803-0203-0403-1303-2303-2704-1508-1108-1208-27
Signal classification5 categories
Patch
5960.8%
Disclosure
2727.8%
General
77.2%
PoC
22.1%
Exploit
22.1%
Referenced assets56 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-173
Disclosure3
2026-02-1811
Disclosure5General2Patch4
2026-02-1932
Disclosure8General1Patch23
2026-02-2030
Disclosure5General3Patch22
2026-02-212
Disclosure2
2026-02-243
Disclosure1Patch2
2026-02-252
Patch2
2026-02-261
Disclosure1
2026-02-271
Patch1
2026-02-281
Patch1
2026-03-021
Patch1
2026-03-041
Patch1
2026-03-131
General1
2026-03-232
Disclosure1Patch1
2026-03-271
Disclosure1
2026-04-151
Patch1
2026-08-111
PoC1
2026-08-122
Exploit1PoC1
2026-08-271
Exploit1
Full discourse20 posts
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-26119 Vendor: Microsoft Product: Windows Admin Center Description: Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. Link: https://github.com/r3vpwnx/cve-2026-26119 #dbugs_vuln

    Post summary

    A proof‑of‑concept and exploit for CVE‑2026‑26119 have been released, demonstrating privilege escalation via improper authentication in Windows Admin Center. No evidence of active exploitation or a patch is cited.

    116088497.9K
    3.6K followersView on X
  • Andrea P@decoder_it
    Disclosure

    Post about Windows Admin Center remote privilege escalation (CVE-2026-26119) has been published, check it out here👇 https://www.semperis.com/blog/what-you-need-to-know-windows-admin-center-remote-privilege-escalation-cve-2026-26119/

    Post summary

    A new Windows Admin Center remote privilege escalation vulnerability (CVE-2026-26119) has been announced and more details are available via the linked blog post.

    035057466.1K
    9.2K followersView on X
  • The Hacker News@TheHackersNews
    Patch

    🛑 Microsoft patched a Windows Admin Center flaw enabling privilege escalation across managed systems. CVE-2026-26119 (CVSS 8.8) stems from improper authentication and could grant rights equal to the running user. 🔗 Read → https://thehackernews.com/2026/02/microsoft-patches-cve-2026-26119.html

    Post summary

    CVE‑2026‑26119 is a privilege escalation flaw in Windows Admin Center with CVSS 8.8; Microsoft has released a patch addressing improper authentication that could grant rights equal to the running user.

    22725097.1K
    1.0M followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    Windows Admin Center'daki CVE-2026-26119 (CVSS: 8.8) güvenlik açığının, kimliği doğrulanmış saldırganların ağ üzerinden ayrıcalık yükselterek uzaktan PowerShell komutları çalıştırmasına olanak sağladığını gösteren PoC yayınlandı. https://github.com/r3vpwnx/cve-2026-26119

    Post summary

    A proof‑of‑concept demonstrating that CVE‑2026‑26119 allows authenticated privilege escalation and remote PowerShell execution was published, with the PoC hosted on GitHub.

    011047282.8K
    2.4K followersView on X
  • Andrea P@decoder_it
    General

    A number of articles are starting to circulate about my recent CVE-2026-26119, many of them clearly AI-generated from the available content and unrelated to the actual vulnerability 😉 More about this soon! 😀

    Post summary

    The post warns that circulating AI‑generated articles about CVE-2026-26119 are unrelated to the real vulnerability, but it offers no concrete details or actionable information.

    0001731.7K
    9.2K followersView on X
  • Nicolas Krassas@Dinosn
    Patch

    Microsoft Patches CVE-2026-26119 Privilege Escalation in Windows Admin Center https://thehackernews.com/2026/02/microsoft-patches-cve-2026-26119.html

    Post summary

    Microsoft has released a patch to address a privilege‑escalation vulnerability (CVE‑2026‑26119) affecting Windows Admin Center.

    020951.2K
    150.9K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Disclosure

    Microsoft reveals critical Windows Admin Center vulnerability (CVE-2026-26119) https://www.helpnetsecurity.com/2026/02/19/windows-admin-center-cve-2026-26119/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    Microsoft announced the discovery of a critical vulnerability (CVE-2026-26119) affecting Windows Admin Center.

    03092529
    192.6K followersView on X
  • IT-Connect.fr@ITConnect_fr
    General

    🛑 Windows Admin Center - CVE-2026-26119 : cette faille dans Windows Admin Center peut mener à la compromission du domaine Mon article à ce sujet 👇 - https://www.it-connect.fr/cve-2026-26119-cette-faille-dans-windows-admin-center-peut-mener-a-la-compromission-du-domaine/ #infosec #cybersecurite #WindowsAdminCenter #Microsoft https://t.co/ggODsuJNL8

    Post summary

    The tweet announces CVE‑2026‑26119 in Windows Admin Center, noting potential domain compromise, but offers no technical specifics, PoC, exploit code, or patch information.

    02042573
    10.9K followersView on X
  • Andrea P@decoder_it
    Exploit

    @ptdbugs Just to be clear, this is NOT a PoC for CVE-2026-26119. It’s a nice python script that authenticates and calls WAC REST endpoints to perform code execution. You could achieve the same thing directly through the web interface. https://www.semperis.com/blog/what-you-need-to-know-windows-admin-center-remote-privilege-escalation-cve-2026-26119/

    Post summary

    The post clarifies that the linked Python script is not a PoC but an exploit that authenticates to WAC REST endpoints for code execution, with no mention of active exploitation or available patches.

    00040382
    9.4K followersView on X
  • Rui Miguel Feio@rfeio
    Patch

    Microsoft has patched CVE-2026-26119, addressing a critical security vulnerability that could be exploited by attackers to compromise affected systems. https://thehackernews.com/2026/02/microsoft-patches-cve-2026-26119.html

    Post summary

    Microsoft has released a patch for CVE‑2026‑26119, a critical vulnerability that could allow attackers to compromise affected systems.

    02020142
    9.2K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos Microsoft ❗ CVE-2026-26119 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-microsoft-6/ https://t.co/aZCKoIRjAx

    Post summary

    The tweet announces a Microsoft vulnerability, CVE-2026-26119, and directs readers to external links for further details.

    01021140
    6.6K followersView on X
  • Help Net Security@helpnetsecurity
    Disclosure

    Microsoft reveals critical Windows Admin Center vulnerability (CVE-2026-26119) - https://www.helpnetsecurity.com/2026/02/19/windows-admin-center-cve-2026-26119/ - @msftsecresponse @decoder_it #WindowsAdminCenter #Sysadmin #Windows #SystemManagement #Vulnerability #CybersecurityNews #InfosecNews #ITsec

    Post summary

    Microsoft announced a critical Windows Admin Center vulnerability (CVE-2026-26119) but did not supply technical details or exploit information in the tweet.

    02010300
    60.0K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: #Microsoft patched a critical vulnerability (CVE-2026-26119, CVSSv3 8.8) in #WindowsAdminCenter. This improper authentication flaw could allow an attacker to elevate privileges and gain access to affected systems. Time to #Patch #Patch #Patch

    Post summary

    Microsoft has released a patch for CVE-2026-26119, an improper authentication flaw in Windows Admin Center that could allow privilege escalation; users are urged to apply the update promptly.

    02010197
    7.2K followersView on X
  • Dr. John D. Johnson@johndjohnson
    Disclosure

    Microsoft reveals critical Windows Admin Center vulnerability (CVE-2026-26119) The technical details are still under wraps, but the vulnerabitily’s CVSS score indicates that it can be exploited remotely with low effort, no user interaction, and minimal (low) privileges (i.e., the attacker must already possess valid low-level access credentials). https://nuel.ink/cm8pU0

    Post summary

    Microsoft has announced a critical vulnerability in Windows Admin Center (CVE-2026-26119) with a high CVSS score indicating remote exploitation potential, but technical details remain undisclosed.

    01010146
    1.1K followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 2026. 2.18 Windows Admin Center の特権の昇格の脆弱性 CVE-2026-26119 Security Vulnerability リリース日: Feb 18, 2026 - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26119

    Post summary

    Microsoft announced a privilege escalation vulnerability (CVE-2026-26119) in Windows Admin Center, providing release information and a vendor advisory link.

    10100139
    89 followersView on X
  • dbugs@ptdbugs
    Disclosure

    📌 Remote Privilege Escalation in Windows Admin Center (CVE‑2026‑26119) Semperis research demonstrates how a vulnerability in "Windows Admin Center" (CVE‑2026‑26119 -> (https://dbugs.ptsecurity.com/vulnerability/PT-2026-20332)) can allow remote privilege escalation and, under certain conditions, full domain compromise. The issue lies in an authentication flaw that allows an attacker to reflect an NTLM token back to the "Windows Admin Center" server. Specifically, a weakness in how "HTTP" requests are handled by a .NET application running on "Kestrel" allows an unprivileged domain user to exploit reflected authentication to gain elevated access to the "Windows Admin Center" server. The vulnerability affects "Windows Admin Center" versions prior to Microsoft’s July 2025 patch. 📎 Article: https://www.semperis.com/blog/what-you-need-to-know-windows-admin-center-remote-privilege-escalation-cve-2026-26119/ #dbugs_attacks

    Post summary

    The post discloses that CVE‑2026‑26119 in Windows Admin Center allows remote privilege escalation via reflected NTLM authentication, and Microsoft will address it with the July 2025 patch.

    00001151
    781 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Windows Admin Center の脆弱性 CVE-2026-26119:認証不備による権限昇格の恐れ https://iototsecnews.jp/2026/02/18/critical-windows-admin-center-vulnerability-allows-privilege-escalation/ 脆弱性 CVE-2026-26119 (CVSS:8.8) の原因は、Windows Admin Center における認証処理の不備 (CWE-287) にあります。限定的な権限を持つ攻撃者であっても、追加のユーザー操作なしに権限昇格が可能となる設計上の問題がありました。その結果、対象アプリケーションを実行するユーザーと同等の特権を取得でき、管理対象サーバの設定変更や機密データへのアクセスにつながる恐れがあります。影響が及ぶのはバージョン 2.6.4 であり、すでに修正版が公開されています。ご利用のチームは、ご注意ください。 #CVE202626119 #Microsoft #Vulnerability #WindowsAdminCenter

    Post summary

    CVE‑2026‑26119 is an authentication flaw in Windows Admin Center 2.6.4 that permits privilege escalation; a patch has already been released.

    01000158
    485 followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    Disclosure

    Microsoft discloses privilege escalation vulnerability in Windows Admin Center (CVE-2026-26119) #CVE202626119 #CyberSecurity #Microsoft #MicrosoftWindows https://www.systemtek.co.uk/2026/02/microsoft-discloses-privilege-escalation-vulnerability-in-windows-admin-center-cve-2026-26119/ https://t.co/9EFpG1Osaj

    Post summary

    Microsoft announced a privilege escalation vulnerability (CVE-2026-26119) affecting Windows Admin Center; the post provides the vulnerability type and CVE ID but lacks PoC, exploit, or patch details.

    1000046
    1.8K followersView on X
  • Ethical Hacking Consultores@EHCGroup
    Patch

    Microsoft revela una vulnerabilidad crítica en el Centro de administración de Windows (CVE-2026-26119). Atención! Una vulnerabilidad crítica en Windows Admin Center permite a atacantes tomar el control total del servidor. Actualiza ya. #ciberseguridad https://www.linkedin.com/pulse/microsoft-revela-una-vulnerabilidad-cr%C3%ADtica-en-el-centro-de-administraci%C3%B3n-gjmve

    Post summary

    The post announces a critical Windows Admin Center vulnerability (CVE‑2026‑26119) and urges immediate patching, without providing detailed technical or exploit information.

    0100095
    4.1K followersView on X
  • Unhinged Cyber@unhingedcyberz
    Disclosure

    Microsoft's patching game is strong, but this CVE-2026-26119 fiasco exposes how Windows Admin Center—meant to be a secure on-prem lifeline—still falls into classic auth blunders. Bold claim: If enterprises keep ignoring these high-CVSS holes (8.8!), they're basically...

    Post summary

    The post highlights the CVE‑2026‑26119 vulnerability in Windows Admin Center, noting its high CVSS score and classic authentication weaknesses, but offers no PoC, exploit, or mitigation details.

    1000036
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftwindows_admin_center---

Explore more