High severity8.8NVD Advisory· Published Jul 14, 2026· Updated Jul 30, 2026
CVE-2026-47301
CVE-2026-47301
Description
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.
Affected products
4- cpe:2.3:a:microsoft:configuration_manager_2503:-:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:configuration_manager_2509:-:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:configuration_manager_2603:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47301nvdVendor Advisory
News mentions
3- Weekly Cyber Security Newsletter Bulletin – Entra ID RCE, Claude Code Ransomware, T-Mobile Cable, Azure Credential Theft +20 StoriesCyber Security News · Aug 23, 2026
- Public Exploit Code Released for Microsoft SCCM Remote Code Execution VulnerabilityCyber Security News · Aug 18, 2026
- Microsoft SCCM Vulnerability Chained to Execute Malicious Code RemotelyCyber Security News · Aug 17, 2026