Windows Admin Center
Vendor:
First CVE: Apr 9, 2019 · Active for 7 years
18
Total CVEs
More Total CVEs than 93% of tracked products
3.6
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Windows Admin Center over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 9, 2019
7 years ago
Most Recent CVE
Jul 17, 2026
7 days ago
CVE Severity & Scoring
Windows Admin Center18 CVEs
33%
61%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local7 (38.9%)
Network11 (61.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (94.4%)
High1 (5.6%)
Unknown0 (0.0%)
User Interaction
None15 (83.3%)
Unknown0 (0.0%)
Required3 (16.7%)
Privileges Required
Low12 (66.7%)
High1 (5.6%)
None5 (27.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-56171HIGH Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network. | Jul 17, 2026 | 7.5 | 37 | NO | NO |
CVE-2026-58631HIGH Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally. | Jul 14, 2026 | 7.8 | 35 | NO | NO |
CVE-2026-56169HIGH Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | Jul 14, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-42834HIGH Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | May 20, 2026 | 7.8 | 34 | NO | NO |
CVE-2026-26119HIGH Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | Feb 17, 2026 | 8.8 | 33 | NO | NO |
CVE-2026-58643MEDIUM Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network. | Jul 16, 2026 | 6.1 | 32 | NO | NO |
CVE-2026-57107HIGH Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | 7.8 | 32 | NO | NO |
CVE-2026-41086HIGH Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | May 12, 2026 | 8.8 | 32 | NO | NO |
CVE-2026-35438HIGH Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | May 12, 2026 | 8.3 | 32 | NO | NO |
CVE-2019-0813CRITICAL An elevation of privilege vulnerability exists when Windows Admin Center improperly impersonates operations in certain situations, aka 'Windows Admin Center Elevation of Privilege | Apr 9, 2019 | 9.8 | 31 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Windows Admin Center
Top CWEs
Versions
No cataloged versions.