Microsoft disclosed CVE-2026-62873, a critical elevation-of-privilege vulnerability in Microsoft 365 Admin Center, on August 6, 2026, according to the Microsoft Security Response Center (MSRC) advisory. The flaw stems from improper verification of a cryptographic signature and could let an unauthorized attacker elevate privileges over a network.
The bug carries a CVSS base score of 9.8, per security researchers at Talos and Dark Reading covering that day's Patch Tuesday, placing it among the highest-severity issues Microsoft fixed that month even though it drew less public attention than actively exploited zero-days.
Key takeaways
- CVE-2026-62873 is a critical elevation-of-privilege flaw in Microsoft 365 Admin Center rated CVSS 9.8.
- The root cause is improper verification of a cryptographic signature (CWE-347), per MSRC.
- Microsoft says the flaw is not publicly disclosed and not exploited in the wild as of the August 6, 2026 advisory.
- It was one of 62 critical CVEs among 421 total disclosed in Microsoft's August 2026 Patch Tuesday, per Cisco Talos.
- Microsoft lists exploitation as unlikely, but recommends applying the latest update as the fix is already available.
Affected
What is CVE-2026-62873?
CVE-2026-62873 is a critical elevation-of-privilege vulnerability in Microsoft 365 Admin Center caused by improper verification of a cryptographic signature, tracked under CWE-347. According to the MSRC advisory published on 2026-08-06, the flaw allows an unauthorized attacker to elevate privileges over a network without needing valid credentials first.
Microsoft assigned the bug a CVSS base score of 9.8, near the top of the scale, reflecting that exploitation requires no prior authentication, no user interaction, and can be triggered remotely over a network. Because Microsoft 365 Admin Center is a cloud-hosted service rather than on-premises software, Microsoft applied the fix server-side; MSRC's advisory directs administrators to confirm the latest update rather than deploy a separate patch package.
- CVSS base score: 9.8
- Weakness: CWE-347, Improper Verification of Cryptographic Signature
- Attack vector: network, unauthorized attacker
- Disclosed: 2026-08-06 by MSRC
Why does this vulnerability matter for IT admins?
Microsoft 365 Admin Center is the console tenant administrators use to manage user accounts, licensing, security policies and service health across an entire organization. A privilege-escalation flaw there is more consequential than a similar bug in a single desktop app, since successful exploitation could hand an attacker administrative control over cloud identity and configuration settings tenant-wide.
Dark Reading's coverage of Microsoft's August 2026 Patch Tuesday grouped CVE-2026-62873 with a small set of CVSS 9.0-plus vulnerabilities that stood out from the month's 421 total disclosures, alongside CVE-2026-59115 (Microsoft Entra Provisioning Service, CVSS 9.9) and CVE-2026-63508 (Planetary Computer Pro). Microsoft's own assessment, however, labels exploitation of CVE-2026-62873 as less likely, based on factors such as attack complexity that MSRC does not detail publicly.
Who is affected and what is the current exploitation status?
Organizations using Microsoft 365 Admin Center are the affected population; because it is a Microsoft-hosted service rather than a locally installed product, Microsoft has not published version numbers, tenant counts, or an install base figure for this CVE.
- MSRC lists exploitation in the wild as 'No' as of the August 6, 2026 advisory.
- MSRC lists public disclosure as 'No,' meaning no prior public writeup or proof-of-concept was known before the advisory.
- Microsoft's exploitability assessment field is marked N/A, and the vulnerability was grouped among CVEs Microsoft considers exploitation 'less likely' for, per Cisco Talos's summary of the release.
- Exploited in the wild: No (per MSRC)
- Publicly disclosed before patch: No
How does August's 421-CVE Patch Tuesday put this flaw in context?
CVE-2026-62873 shipped as one of 421 CVEs Microsoft addressed in its August 2026 security update, of which 62 were rated critical, according to Cisco Talos. Dark Reading reported the same update cycle fixed two zero-day vulnerabilities, including the actively exploited CVE-2026-68820 in Windows Ancillary Function Driver for WinSock and a second, publicly known flaw, CVE-2026-62832, in Windows User Profile Service.
Threat-intelligence firm Hive Pro's advisory (TA2026230) put the August release in a broader frame: 421 vulnerabilities across Windows, SharePoint Server, GitHub Copilot, Visual Studio Code and Azure SQL Database, of which 39 CVEs were flagged as at risk of active exploitation. Fortra's Tyler Reguly told Dark Reading that most of the volume is covered by routine cumulative updates, easing the practical burden despite the headline count.
- 421 total CVEs disclosed in August 2026 Patch Tuesday (per Cisco Talos)
- 62 critical-severity CVEs in the same release
- 1 actively exploited zero-day (CVE-2026-68820) named in the same cycle
What should admins do to mitigate CVE-2026-62873?
MSRC's remediation guidance for CVE-2026-62873 is to apply the latest security update for the affected product. Because Microsoft 365 Admin Center runs as a cloud service, Microsoft is responsible for deploying the fix on its backend, and the advisory does not list a downloadable patch package or a workaround for customers to apply themselves.
- Review Microsoft 365 Admin Center sign-in and audit logs for anomalous privilege changes made around and after 2026-08-06.
- Confirm tenant administrators use conditional access and multi-factor authentication on Admin Center accounts, since privilege-escalation bugs compound the risk of any compromised admin session.
- Track the MSRC Update Guide entry for CVE-2026-62873 for any revision to the exploitability assessment or exploitation status.
What else should security teams watch this Patch Tuesday cycle?
Security researchers quoted by Dark Reading urged defenders to prioritize the actively exploited CVE-2026-68820 and the publicly known CVE-2026-62832 first, since Microsoft confirmed real-world attacks on the former. Cohesity's Amol Sarwate noted the two flaws could be chained to turn limited access into full system compromise, a higher immediate risk than CVE-2026-62873's unconfirmed exploitation status.
Zero Day Initiative's Dustin Childs separately flagged CVE-2026-62878, a wormable CVSS 9.8 remote-code-execution bug in Windows DNS Server, as deserving fast testing and deployment on internet-facing servers despite Microsoft's 'less likely' exploitation label. Admins should treat Microsoft's likelihood ratings as guidance rather than certainty when scheduling patch rollouts across the month's 421 disclosures.
Timeline
Impact & actions
CVE-2026-62873 lets an unauthorized network attacker escalate privileges in Microsoft 365 Admin Center by exploiting improper verification of a cryptographic signature, a flaw Microsoft rates critical with a CVSS score of 9.8.
Security: Microsoft assesses the flaw as not exploited in the wild and not publicly disclosed as of the August 6, 2026 advisory, but its 9.8 CVSS score places it among the highest-severity issues in that month's release.
Recommended actions · Medium urgency
- 1Apply Microsoft's published fix for CVE-2026-62873 as soon as it is available for your tenant
- 2Review Microsoft 365 Admin Center audit logs for unexpected privilege changes
- 3Track the CVE in your August 2026 Patch Tuesday remediation plan alongside other critical fixes
Technical details
- CVEs
- CVE-2026-62873
- CVSS
- 9.8
- Attack vector
- network
- Affected versions
- Microsoft 365 Admin Center
Mitigations
- Apply the Microsoft security update for Microsoft 365 Admin Center referenced in the MSRC advisory
Response
Vendor
Customer guidance
Microsoft directs admins to apply the latest security update for Microsoft 365 Admin Center referenced in the MSRC advisory; no separate workaround is listed.
Updates
Microsoft published the initial advisory for CVE-2026-62873 as part of its August 2026 Patch Tuesday release.
FAQ
What is CVE-2026-62873?
CVE-2026-62873 is a critical elevation-of-privilege vulnerability in Microsoft 365 Admin Center caused by improper verification of a cryptographic signature (CWE-347), letting an unauthorized attacker escalate privileges over a network, per the MSRC advisory.
What is the CVSS score for CVE-2026-62873?
Microsoft and Cisco Talos both list a CVSS base score of 9.8 for CVE-2026-62873.
Has CVE-2026-62873 been exploited?
No. Microsoft's MSRC advisory states the flaw was not publicly disclosed and had not been exploited in the wild as of the August 6, 2026 release.
Is a fix available for CVE-2026-62873?
Yes. Microsoft published the fix alongside the advisory and lists it as available; admins should apply the update through their normal Microsoft 365 admin channels.
How does CVE-2026-62873 fit into August 2026 Patch Tuesday?
It was one of 62 critical-severity CVEs among 421 total vulnerabilities Microsoft disclosed that month, alongside an actively exploited zero-day, CVE-2026-68820, in the Windows Ancillary Function Driver for WinSock, according to Cisco Talos.
The bottom line
Microsoft patched CVE-2026-62873, a critical CVSS 9.8 elevation-of-privilege flaw in Microsoft 365 Admin Center tied to improper cryptographic signature verification, as part of its August 6, 2026 Patch Tuesday.
What happens next
What to do




-640x640.webp&w=3840&q=75)

