2026-06-06 is live. RBL, certificate, and uptime monitoring — now in public beta.

News

Microsoft fixes CVE-2026-26119 privilege-escalation bug in Windows Admin Center


Microsoft has issued a patch for a serious security vulnerability in Windows Admin Center that could allow an attacker to escalate their privileges. The vulnerability has been tracked as CVE-2026-26119.

Windows Admin Center is an on-premises, browser-driven management suite that administrators use to administer Windows clients, servers, and clusters without relying on cloud-hosted services.

The flaw has been rated high severity, carrying a CVSS score of 8.8 out of 10. According to Microsoft’s advisory published on February 17, 2026, the issue stems from improper authentication in Windows Admin Center and could allow a network-based, authenticated attacker to obtain the rights associated with the account running the vulnerable application.

Microsoft credited Andrea Pierini of Semperis for discovering and reporting the issue. The company addressed the problem in Windows Admin Center version 2511, which was released in December 2025.

While Microsoft has not reported any confirmed exploitation in real-world attacks, the vulnerability has been given an “Exploitation More Likely” designation.

Technical specifics about CVE-2026-26119 have not been publicly released yet. However, Pierini posted on LinkedIn, suggesting that under certain circumstances, the bug could be leveraged by a regular user to achieve a complete domain compromise.

First published on February 19, 2026.
Last updated on July 15, 2026.