Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2026-26119 PoC: Windows Admin Center authenticated RCE

Summary

A PoC for CVE-2026-26119, an authenticated remote code execution vulnerability in Windows Admin Center, exploiting the WinREST/PowerShell invokeCommand path with steps to obtain a reverse shell.

Why it matters

The PoC shows that a low-privileged valid account can turn the flaw into remote command execution over the network. Upgrade to Windows Admin Center 2.6.4 or later and review WAC accounts and anomalous PowerShell activity.
Vendor
Microsoft
Product
Windows Admin Center
Affected versions
< 2.6.4
CVSS
8.8
Published
Collected

original ↗

Related coverage

back