Cyber Press reports that a severe vulnerability in Microsoft's Azure Active Directory integration for Windows Admin Center allowed attackers with local admin access to bypass authentication and seize control of any machine in the same Azure tenant.Tracked as CVE-2026-20965, the flaw resided in the SSO implementation's improper validation of two access tokens, enabling an attacker to combine a stolen privileged token with a forged Proof-of-Possession token to impersonate a victim. Exploitation required an attacker to first gain local administrator privileges on an Azure VM or Arc-connected machine, then capture a token when a privileged user connected via the Azure Portal.According to researchers at Cymulate, successful exploitation allowed privilege escalation, remote command execution, and lateral movement across all accessible WAC-enabled systems, breaching cloud boundaries to pivot across resource groups. Microsoft patched the issue in Windows Admin Center Azure Extension version 0.70.00 on January 14, 2026. Security teams are urged to update immediately and monitor for suspicious virtual accounts following a specific naming format to detect potential abuse.
Identity, Cloud Security, Vulnerability Management, Patch/Configuration Management

Critical Azure AD flaw in Windows Admin Center patched

(Adobe Stock)

Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



