
Armadin researcher @mhskai2017 has uncovered two authenticated RCE vulnerability affecting Dell OpenManage Integration and Lenovo XClarity Integration with Windows Admin Center (CVE-2026-101207 and CVE-2026-65949, both High severity CVSS 8.8). A domain user credential is enough to gain SYSTEM on the WAC host, hijack admin sessions, and move laterally to every asset it manages. Patch immediately. Advisory and mitigation details: https://www.dell.com/support/kbdoc/en-us/000515026/dsa-2026-442-security-update-for-dell-openmanage-integration-with-microsoft-windows-admin-center and https://support.lenovo.com/us/en/product_security/ps500868
