SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-58643

MEDIUM · CVSS 6.1 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Windows Admin Center is vulnerable to cross-site scripting (XSS) due to improper input neutralization during web page generation. This flaw enables unauthorized attackers to execute spoofing attacks over the network, potentially compromising user sessions or manipulating content. Organizations using Windows Admin Center should prioritize addressing this vulnerability to mitigate risks related to unauthorized access and data integrity.

CVE
CVE-2026-58643
Severity
MEDIUM
CVSS
6.1
EPSS
0.24%
Windows

Original NVD Description

Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.

Related CVEs

Other vulnerabilities affecting the same vendor(s)