Critical Vulnerabilities in Microsoft SCCM Enable Remote Code Execution for $58

Critical Vulnerabilities in Microsoft SCCM Enable Remote Code Execution for $58

First seen 13 Aug 2026, 21:57 UTC CsoonlineXmcyberTechtimeswww.sentinelone.comwww.bleepingcomputer.com+3 72.0

Article Content

Browse articles
ThreatCluster

Security researchers from XM Cyber have identified a chain of vulnerabilities in Microsoft System Center Configuration Manager (SCCM) that allows standard domain users to achieve remote code execution. The attack exploits multiple flaws, including CVE-2026-47301, which was patched in July 2026, but three additional vulnerabilities remain unaddressed until the upcoming ConfigMgr 2609 release in October. The attack can be initiated by any authenticated user with network access to the SCCM environment, enabling them to gain SYSTEM-level control over the primary site server and all managed endpoints. The vulnerabilities include a broken authorization check, a path traversal flaw dubbed 'CabSlip', and weak code-signing validation that can be bypassed with a $58 certificate. With over 100 million active SCCM users, the potential impact is significant, and organizations are urged to secure their systems against these vulnerabilities.

Key Points: • Standard domain users can exploit SCCM vulnerabilities for remote code execution. • CVE-2026-47301 was patched, but three additional vulnerabilities remain unaddressed. • An attacker can gain SYSTEM-level control over all managed endpoints with network access.

Timeline

2024-10-08
CVE-2024-43468 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-07-08
CVE-2025-47178 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-14
CVE-2026-47301 published
Microsoft released a patch for the initial authorization flaw in SCCM, but other vulnerabilities remain unpatched.
Techtimes
2026-08-04
First public PoC for CVE-2026-47301
XM Cyber disclosed a proof-of-concept exploit demonstrating the vulnerability's potential for remote code execution.
Xmcyber
2026-08-13
Research findings published
XM Cyber researchers detailed the exploit chain, highlighting the severity and potential impact on SCCM users.
CSO Online
2026-08-14
CISA issues advisory
CISA ordered U.S. government agencies to secure systems against the identified vulnerabilities in SCCM.
BleepingComputer