Critical Remote Code Execution Flaw in Microsoft SCCM Discovered

Critical Remote Code Execution Flaw in Microsoft SCCM Discovered

First seen 13 Aug 2026, 21:57 UTC CsoonlineXmcyber 84% similarity 74.0

Article Content

Browse articles
ThreatCluster

XM Cyber identified a series of vulnerabilities in Microsoft SCCM that allow standard domain users to achieve remote code execution without administrative privileges. The exploit chain targets the primary site server, potentially compromising all managed clients. The vulnerabilities include a broken authorization check in the AdminService API, a path traversal flaw dubbed 'CabSlip', weak code-signing validation, and an unsigned DLL-loading path. Microsoft assigned CVE-2026-47301 for one of the vulnerabilities, which was patched in July 2026, but the remaining vulnerabilities are unpatched and expected to be addressed in October 2026. The attack can escalate privileges to 'NT AUTHORITY\SYSTEM', affecting over 100 million active users of SCCM. Until the complete fix is released, organizations remain at risk.

Key Points: • A series of vulnerabilities in Microsoft SCCM allows remote code execution by standard users. • CVE-2026-47301 was patched in July, but other vulnerabilities remain unaddressed until October. • The exploit chain can compromise all managed clients once the primary site server is breached.

ThreatCluster AI How this analysis works

Timeline

2026-05-23
Vulnerabilities reported to Microsoft
XM Cyber disclosed multiple vulnerabilities in SCCM to Microsoft, including a critical authorization flaw.
Xmcyber
2026-07-14
CVE-2026-47301 published
Microsoft published a fix for the broken authorization flaw in SCCM, tracked as CVE-2026-47301.
Xmcyber
2026-08-04
First public PoC released
XM Cyber released a proof of concept demonstrating the exploit chain for SCCM vulnerabilities.
Csoonline
2026-08-13
Current status of vulnerabilities
As of today, the remaining vulnerabilities in SCCM are unpatched and pose a significant risk to organizations.
Xmcyber

Community

Browse all →

Tracked Entities in This Story