Identity, Cloud Security, Vulnerability Management, Patch/Configuration Management

Critical Azure AD flaw in Windows Admin Center patched

Microsoft Azure company logo on a website with blurry stock market developments in the background, seen on a computer screen through a magnifying glass.

Cyber Press reports that a severe vulnerability in Microsoft's Azure Active Directory integration for Windows Admin Center allowed attackers with local admin access to bypass authentication and seize control of any machine in the same Azure tenant.

Tracked as CVE-2026-20965, the flaw resided in the SSO implementation's improper validation of two access tokens, enabling an attacker to combine a stolen privileged token with a forged Proof-of-Possession token to impersonate a victim. Exploitation required an attacker to first gain local administrator privileges on an Azure VM or Arc-connected machine, then capture a token when a privileged user connected via the Azure Portal.

According to researchers at Cymulate, successful exploitation allowed privilege escalation, remote command execution, and lateral movement across all accessible WAC-enabled systems, breaching cloud boundaries to pivot across resource groups. Microsoft patched the issue in Windows Admin Center Azure Extension version 0.70.00 on January 14, 2026. Security teams are urged to update immediately and monitor for suspicious virtual accounts following a specific naming format to detect potential abuse.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds