Microsoft Windows Admin Center
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Microsoft Windows Admin Center.
Recent Microsoft Windows Admin Center Security Advisories
| Advisory | Title | Published |
|---|---|---|
| CVE-2026-58643 | CVE-2026-58643 Windows Admin Center Spoofing Vulnerability | July 16, 2026 |
| CVE-2026-56185 | CVE-2026-56185 Windows Admin Center Information Disclosure Vulnerability | July 14, 2026 |
| CVE-2026-56169 | CVE-2026-56169 Windows Admin Center Elevation of Privilege Vulnerability | July 14, 2026 |
| CVE-2026-57107 | CVE-2026-57107 Windows Admin Center Elevation of Privilege Vulnerability | July 14, 2026 |
| CVE-2026-58631 | CVE-2026-58631 Windows Admin Center (WAC) Remote Code Execution Vulnerability | July 14, 2026 |
| CVE-2026-56196 | CVE-2026-56196 Windows Admin Center (WAC) Remote Code Execution Vulnerability | July 14, 2026 |
| CVE-2026-56197 | CVE-2026-56197 Windows Admin Center (WAC) Remote Code Execution Vulnerability | July 14, 2026 |
| CVE-2026-35438 | CVE-2026-35438 Windows Admin Center Elevation of Privilege Vulnerability | May 12, 2026 |
| CVE-2026-41086 | CVE-2026-41086 Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability | May 12, 2026 |
| CVE-2026-32196 | CVE-2026-32196 Windows Admin Center Spoofing Vulnerability | April 14, 2026 |
By the Year
In 2026 there have been 11 vulnerabilities in Microsoft Windows Admin Center with an average score of 7.7 out of ten. Last year, in 2025 Windows Admin Center had 2 security vulnerabilities published. That is, 9 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.65.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 11 | 7.65 |
| 2025 | 2 | 7.00 |
| 2024 | 1 | 7.30 |
| 2023 | 1 | 6.80 |
| 2022 | 0 | 0.00 |
| 2021 | 1 | 4.30 |
| 2020 | 0 | 0.00 |
| 2019 | 1 | 9.80 |
It may take a day or so for new Windows Admin Center vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Microsoft Windows Admin Center Security Vulnerabilities
Jul 2026: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-56171
7.1 - High
- July 17, 2026
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
Privacy violation
Jul 2026: Windows Admin Center Spoofing Vulnerability
CVE-2026-58643
6.1 - Medium
- July 16, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
XSS
Jul 2026: Windows Admin Center (WAC) Remote Code Execution Vulnerability
CVE-2026-56197
8.8 - High
- July 14, 2026
Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network.
Command Injection
Jul 2026: Windows Admin Center (WAC) Remote Code Execution Vulnerability
CVE-2026-56196
8.8 - High
- July 14, 2026
Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.
Relative Path Traversal
Jul 2026: Windows Admin Center (WAC) Remote Code Execution Vulnerability
CVE-2026-58631
7.8 - High
- July 14, 2026
Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.
AuthZ
Jul 2026: Windows Admin Center Elevation of Privilege Vulnerability
CVE-2026-57107
7.8 - High
- July 14, 2026
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.
authentification
Jul 2026: Windows Admin Center Information Disclosure Vulnerability
CVE-2026-56185
6.5 - Medium
- July 14, 2026
Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.
authentification
Jul 2026: Windows Admin Center Elevation of Privilege Vulnerability
CVE-2026-56169
8.1 - High
- July 14, 2026
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
authentification
May 2026: Windows Admin Center Elevation of Privilege Vulnerability
CVE-2026-35438
8.3 - High
- May 12, 2026
Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
AuthZ
Apr 2026: Windows Admin Center Spoofing Vulnerability
CVE-2026-32196
6.1 - Medium
- April 14, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
XSS
Feb 2026: Windows Admin Center Elevation of Privilege Vulnerability
CVE-2026-26119
8.8 - High
- February 17, 2026
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
authentification
Dec 2025: Windows Admin Center Elevation of Privilege Vulnerability
CVE-2025-64669
7.8 - High
- December 11, 2025
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally.
Authorization
Apr 2025: Windows Admin Center in Azure Portal Information Disclosure Vulnerability
CVE-2025-29819
6.2 - Medium
- April 08, 2025
External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized attacker to disclose information locally.
External Control of File Name or Path
Windows Admin Center Info Disclosure via Improper Permission Handling
CVE-2024-43475
7.3 - High
- September 10, 2024
Microsoft Windows Admin Center Information Disclosure Vulnerability
Buffer Over-read
Windows Admin Center Spoofing Vulnerability (CVE-2023-29347)
CVE-2023-29347
6.8 - Medium
- July 11, 2023
Windows Admin Center Spoofing Vulnerability
Windows Admin Center Security Feature Bypass Vulnerability
CVE-2021-27066
4.3 - Medium
- March 11, 2021
Windows Admin Center Security Feature Bypass Vulnerability
An elevation of privilege vulnerability exists when Windows Admin Center improperly impersonates operations in certain situations
CVE-2019-0813
9.8 - Critical
- April 09, 2019
An elevation of privilege vulnerability exists when Windows Admin Center improperly impersonates operations in certain situations, aka 'Windows Admin Center Elevation of Privilege Vulnerability'.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Microsoft Windows Admin Center or by Microsoft? Click the Watch button to subscribe.