🟠 High | Source: Microsoft Security Response Center
CVE-2026-56197 is a remote code execution vulnerability in Windows Admin Center (WAC), a browser-based management tool used to administer Windows servers and Azure infrastructure. The latest update from Microsoft is an administrative acknowledgement change only, with no new technical details or patch information. Despite the informational nature of this update, the underlying RCE vulnerability remains a serious concern for any organisation running WAC.
Security Architect’s Take: Ensure Windows Admin Center is not exposed to the public internet and is accessible only via VPN or Azure AD App Proxy; verify that the latest WAC patch addressing CVE-2026-56197 has been applied across all management nodes and audit who has access to WAC instances.
Original advisory: CVE-2026-56197 Windows Admin Center (WAC) Remote Code Execution Vulnerability