CVE-2026-20967 is a high-severity improper input validation vulnerability affecting Microsoft System Center Operations Manager (SCOM). Rated with a CVSS score of 8.8, this flaw allows an authorized attacker to remotely elevate privileges over a network with low attack complexity. Exploitation could lead to a complete compromise of confidentiality, integrity, and availability of the affected system. While not currently listed on the CISA KEV catalog and lacking public exploit code, its existence was noted in March 2026 Patch Tuesday summaries. Organizations utilizing SCOM should prioritize patching to address this significant risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:system_center_operations_manager:2019:-:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:system_center_operations_manager:2019:update_rollup_1:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:system_center_operations_manager:2019:update_rollup_1_hotfix:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:system_center_operations_manager:2019:update_rollup_2:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:system_center_operations_manager:2019:update_rollup_2_hotfix:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.