Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-62873: Microsoft 365 Admin Center Privilege Elevation via Signature Verification

CVE-2026-62873 · published 28 days ago
Summary

The Microsoft 365 Admin Center has a weakness that could allow an attacker to gain higher levels of access to the system than they should have. This is a concern because an attacker could use this vulnerability to take control of sensitive areas of the system. Microsoft should be contacted to determine if a patch or update is available to fix this issue.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
microsoft microsoft 365 admin center -
microsoft windows_admin_center All versions
cpe:2.3:a:microsoft:windows_admin_center:-:*:*:*:*:*:*:*
Original advisory text
Microsoft 365 Admin Center Elevation of Privilege Vulnerability
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-347Improper Verification of Cryptographic Signature
Timeline
Published6 Aug 2026
Updated3 Sep 2026
First seen7 Aug 2026
Sources
CVE-2026-62873 · MITRE
Monitor software like this
Free during beta