SYS::ONLINE
Wasteland.
Briefs1769
Issues22
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-62873 2026-08-06

CVE-2026-62873: Critical Signature Verification Flaw in Microsoft 365 Admin Center

"Microsoft has disclosed a critical (CVSS 9.8) improper cryptographic signature verification vulnerability in the Microsoft 365 Admin Center that allows an unauthenticated attacker to elevate privileges over a network."

Microsoft has disclosed a critical (CVSS 9.8) improper cryptographic signature verification vulnerability in the Microsoft 365 Admin Center that allows an unauthenticated attacker to elevate privileges over a network.

What Is It

CVE-2026-62873 is an improper verification of cryptographic signature flaw (CWE-347) in Microsoft 365 Admin Center. According to Microsoft's advisory, the weakness "allows an unauthorized attacker to elevate privileges over a network."

The CVSS 3.1 vector, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, describes the worst practical combination for a privilege escalation bug: network-reachable, low attack complexity, no privileges required, and no user interaction. Impact is high across confidentiality, integrity, and availability, producing a base score of 9.8 (CRITICAL) with a maximum exploitability subscore of 3.9.

Why It Matters

The Microsoft 365 Admin Center is the control plane for tenant identity, licensing, and service configuration. A signature verification failure there means an attacker may be able to present forged or manipulated signed material and have it accepted as trusted; reaching elevated privileges with no credentials at all.

CISA's SSVC assessment scores this as automatable: yes with technicalImpact: total, meaning an attacker could reliably script the attack chain at scale and gain full control of the affected component. SSVC lists exploitation: none, which records that CISA had not observed or received reports of public exploitation when it made that assessment. That is a statement about what has been reported, not evidence that exploitation is not occurring; for an exclusively hosted service, customers have little independent visibility into attacks against the provider's infrastructure.

What's Vulnerable

Microsoft tagged this CVE as exclusively-hosted-service. No affected CPE entries were published in the NVD record.

Patch Status

Because this is an exclusively hosted service, remediation is handled by Microsoft on the service side rather than through customer-deployed patches. No customer action is enumerated in the supplied data.

The NVD record carries no CISA Known Exploited Vulnerabilities entry, the KEV fields are empty, so there is no KEV-mandated remediation due date associated with this CVE. Readers can confirm current KEV status directly against CISA's catalog, linked below; KEV additions happen on CISA's own schedule and can post after an NVD record is created.

The NVD record is in Received status, meaning NVD analysis is not yet complete and the details above may change as the record is enriched. Administrators should consult the MSRC update guide entry for current service remediation status.

Sources