CVE-2026-32196Disclosure(microsoft / windows_admin_center)

MEDIUMCVSS 6.1 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft windows_admin_center systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_admin_center

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-04-15); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
windows_admin_center

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-15: 3Mentions · 2026-04-17: 1Mentions · 2026-04-24: 1PoC Mentioned / Linked · 2026-04-15: 1PoC Mentioned / Linked · 2026-04-17: 1Exploit Tool / Code · 2026-04-17: 1Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-04-17: 1Technical Details · 2026-04-15: 3Technical Details · 2026-04-24: 104-1504-1704-24
Signal classification3 categories
Disclosure
240.0%
PoC
240.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-153
Disclosure1Patch1PoC1
2026-04-171
PoC1
2026-04-241
Disclosure1
Full discourse5 posts
  • Ruben Labs@RubenLabs
    PoC

    New XSS2RCE in Azure Windows Admin Center! I am happy to share our latest findings, CVE-2026-32196, a critical unauthenticated vulnerability allowing one-click remote code execution. An attacker can craft a malicious legitimate gateway URL that, when visited by a privileged Azure admin, triggers a response-based XSS in WAC’s error handling. This results in JavaScript execution under the WAC origin, which translates to arbitrary PowerShell execution on every managed server the victim has access to (no credentials required). On on-premises deployments, the same chain allows theft of Azure access and refresh tokens from local storage, enabling full tenant impersonation and lateral movement into EntraID and Azure. Full blog: https://cymulate.com/blog/cve-2026-32196-one-click-rce-windows-admin-center/

    Post summary

    The post announces CVE‑2026‑32196, a critical unauthenticated vulnerability in Azure Windows Admin Center that exploits XSS to achieve one‑click remote code execution and token theft, with technical details and a reference to a blog containing the proof of concept.

    021185407.1K
    247 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Azure WAC の脆弱性 CVE-2026-32196:オンプレミス環境での未認証ワンクリック RCE に注意 https://iototsecnews.jp/2026/04/17/one-click-rce-in-azure-windows-admin-center-allow-attacker-to-execute-arbitrary-commands/ この問題の原因は、Windows Admin Center (WAC) の設計において、”サーバーからの返信内容” や “接続先の URL” などを 正しく検証する仕組みが不足していたことにあります。この脆弱性 CVE-2026-32196 は、3 つの弱点が組み合わさることで、きわめて危険な攻撃へとエスカレートします。さらに、オンプレミス環境では、Azure のログイン情報がブラウザ内に不用心に保存されているため、攻撃者はたった一度のクリックで管理対象のサーバを侵害し、リモートからクラウド全体の権限を盗み取ることなどが可能になります。ご利用のチームは、ご注意ください。 #AzureWAC #CVE202632196 #Microsoft #Vulnerability

    Post summary

    The article announces a design flaw in Azure WAC that enables an unauthenticated one‑click RCE, providing technical details but no PoC, patch, or active exploitation evidence.

    01000130
    486 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Patch

    🚨 Critical One-Click RCE in #Windows Admin Center Exposes Enterprise Networks – #CVE-2026-32196 Urgent Patch Analysis + Video https://undercodetesting.com/critical-one-click-rce-in-windows-admin-center-exposes-enterprise-networks-cve-2026-32196-urgent-patch-analysis-video/ Educational Purposes!

    Post summary

    The tweet highlights a critical One‑Click remote code execution in Windows Admin Center (CVE‑2026‑32196) and stresses the immediate need for an urgent patch.

    0100058
    491 followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼ #Microsoft: Proof of Concept (#PoC) per lo sfruttamento della vulnerabilità CVE-2026-32196 relativa a #WindowsAdminCenter, risulta disponibile in rete ⚠ Ove non provveduto, si raccomanda l’aggiornamento tempestivo del software interessato https://x.com/csirt_it/status/2044351897658663293

    Post summary

    A Proof of Concept for CVE-2026-32196 against Windows Admin Center is available online, and users are advised to update the software promptly.

    0000054
    610 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32196 Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over … https://www.cve.org/CVERecord?id=CVE-2026-32196

    Post summary

    The text merely announces CVE‑2026‑32196, a cross‑site scripting flaw in Windows Admin Center, without providing any PoC, exploit, or patch details.

    00000158
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftwindows_admin_center---

Explore more