Microsoft Windows Admin Center Cross-Site Scripting Vulnerability Allowing Spoofing

Vulnerability

A cross-site scripting vulnerability has been identified in Windows Admin Center. This issue arises from improper input neutralization during web page generation, allowing an unauthorized attacker to perform spoofing over the network. The vulnerability affects all versions of Windows Admin Center through 2511.

Impact

Exploitation of this vulnerability could lead to address bar spoofing, where a malicious website could manipulate the URL display in the browser, potentially facilitating a phishing attack.

Remediation

Users can download the security update for Windows Admin Center from the Microsoft Update Catalog.

Added: Jul 16, 2026, 10:36 PM
Updated: Jul 16, 2026, 10:36 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
1.7
exploitability
5.8
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.