← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 13, 2026 · 12:14via CSO Online

It took $58 to break Microsoft’s SCCM, but a patch made it harder

Brief

Researchers at XM Cyber found that a standard domain user with no Microsoft SCCM privileges can chain multiple flaws to reach remote code execution, although the attack does require network access to the SCCM environment.

Enterprises use Microsoft System Center Configuration Manager ( SCCM ) to deploy operating systems, manage patches, distribute software, and monitor compliance across large Windows fleets. XM Cyber’s attack can move from an ordinary domain account to code execution as “NT AUTHORITY\SYSTEM” on the primary site server.

“After the Site Server is compromised, all of its managed clients are compromised as well, which usually means taking over all the company assets,” XM Cyber’s Omri Baso told CSO.

Read more on CSO Online