Status: UPDATED
| Advisory ID: CVE-2026-96940
Key Details
| CVE | CVE-2026-96940 |
| CVSS Score / Version | 8.8 (High) / CVSS v3.1 |
| Updated | 2026-10-02 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Microsoft Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Microsoft Exchange Server 2019 Cumulative Update 15, and Microsoft Microsoft Exchange Server Subscription Edition RTM |
| Classified as | CWE-1390 (Weak Authentication) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
What to Do
Monitor Microsoft's web page for any future patch releases.
References