Windows Admin Center Microsoft Windows Admin Center

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Microsoft Windows Admin Center.

Recent Microsoft Windows Admin Center Security Advisories

Advisory Title Published
CVE-2026-58643 CVE-2026-58643 Windows Admin Center Spoofing Vulnerability July 16, 2026
CVE-2026-56185 CVE-2026-56185 Windows Admin Center Information Disclosure Vulnerability July 14, 2026
CVE-2026-56169 CVE-2026-56169 Windows Admin Center Elevation of Privilege Vulnerability July 14, 2026
CVE-2026-57107 CVE-2026-57107 Windows Admin Center Elevation of Privilege Vulnerability July 14, 2026
CVE-2026-58631 CVE-2026-58631 Windows Admin Center (WAC) Remote Code Execution Vulnerability July 14, 2026
CVE-2026-56196 CVE-2026-56196 Windows Admin Center (WAC) Remote Code Execution Vulnerability July 14, 2026
CVE-2026-56197 CVE-2026-56197 Windows Admin Center (WAC) Remote Code Execution Vulnerability July 14, 2026
CVE-2026-35438 CVE-2026-35438 Windows Admin Center Elevation of Privilege Vulnerability May 12, 2026
CVE-2026-41086 CVE-2026-41086 Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability May 12, 2026
CVE-2026-32196 CVE-2026-32196 Windows Admin Center Spoofing Vulnerability April 14, 2026

By the Year

In 2026 there have been 11 vulnerabilities in Microsoft Windows Admin Center with an average score of 7.7 out of ten. Last year, in 2025 Windows Admin Center had 2 security vulnerabilities published. That is, 9 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.65.




Year Vulnerabilities Average Score
2026 11 7.65
2025 2 7.00
2024 1 7.30
2023 1 6.80
2022 0 0.00
2021 1 4.30
2020 0 0.00
2019 1 9.80

It may take a day or so for new Windows Admin Center vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Microsoft Windows Admin Center Security Vulnerabilities

Jul 2026: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-56171 7.1 - High - July 17, 2026

Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.

Privacy violation

Jul 2026: Windows Admin Center Spoofing Vulnerability
CVE-2026-58643 6.1 - Medium - July 16, 2026

Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.

XSS

Jul 2026: Windows Admin Center (WAC) Remote Code Execution Vulnerability
CVE-2026-56197 8.8 - High - July 14, 2026

Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network.

Command Injection

Jul 2026: Windows Admin Center (WAC) Remote Code Execution Vulnerability
CVE-2026-56196 8.8 - High - July 14, 2026

Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.

Relative Path Traversal

Jul 2026: Windows Admin Center (WAC) Remote Code Execution Vulnerability
CVE-2026-58631 7.8 - High - July 14, 2026

Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.

AuthZ

Jul 2026: Windows Admin Center Elevation of Privilege Vulnerability
CVE-2026-57107 7.8 - High - July 14, 2026

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.

authentification

Jul 2026: Windows Admin Center Information Disclosure Vulnerability
CVE-2026-56185 6.5 - Medium - July 14, 2026

Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

authentification

Jul 2026: Windows Admin Center Elevation of Privilege Vulnerability
CVE-2026-56169 8.1 - High - July 14, 2026

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

authentification

May 2026: Windows Admin Center Elevation of Privilege Vulnerability
CVE-2026-35438 8.3 - High - May 12, 2026

Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

AuthZ

Apr 2026: Windows Admin Center Spoofing Vulnerability
CVE-2026-32196 6.1 - Medium - April 14, 2026

Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.

XSS

Feb 2026: Windows Admin Center Elevation of Privilege Vulnerability
CVE-2026-26119 8.8 - High - February 17, 2026

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

authentification

Dec 2025: Windows Admin Center Elevation of Privilege Vulnerability
CVE-2025-64669 7.8 - High - December 11, 2025

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally.

Authorization

Apr 2025: Windows Admin Center in Azure Portal Information Disclosure Vulnerability
CVE-2025-29819 6.2 - Medium - April 08, 2025

External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized attacker to disclose information locally.

External Control of File Name or Path

Windows Admin Center Info Disclosure via Improper Permission Handling
CVE-2024-43475 7.3 - High - September 10, 2024

Microsoft Windows Admin Center Information Disclosure Vulnerability

Buffer Over-read

Windows Admin Center Spoofing Vulnerability (CVE-2023-29347)
CVE-2023-29347 6.8 - Medium - July 11, 2023

Windows Admin Center Spoofing Vulnerability

Windows Admin Center Security Feature Bypass Vulnerability
CVE-2021-27066 4.3 - Medium - March 11, 2021

Windows Admin Center Security Feature Bypass Vulnerability

An elevation of privilege vulnerability exists when Windows Admin Center improperly impersonates operations in certain situations
CVE-2019-0813 9.8 - Critical - April 09, 2019

An elevation of privilege vulnerability exists when Windows Admin Center improperly impersonates operations in certain situations, aka 'Windows Admin Center Elevation of Privilege Vulnerability'.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Microsoft Windows Admin Center or by Microsoft? Click the Watch button to subscribe.

Microsoft
Vendor

subscribe