Story perspectives
Microsoft Fixes Critical Windows Flaw for Domain Security
2/21/2026
1 of 1
Story summary
- Microsoft patched a high-severity Windows Admin Center flaw, CVE-2026-26119, CVSS 8.8.
- Discovered by Semperis researcher Andrea Pierini, the vulnerability enables an authorized attacker to escalate privileges due to improper authentication.
- It could allow full domain compromise starting from a standard user account.
- Microsoft released a fix in December 2025, and the vulnerability is assessed as "Exploitation More Likely," with no reports of in-the-wild exploitation.
