← All Advisories

CVE-2026-96940

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-96940

Key Details

CVECVE-2026-96940
CVSS Score / Version8.8 (High) / CVSS v3.1
Updated2026-10-02
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsMicrosoft Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Microsoft Exchange Server 2019 Cumulative Update 15, and Microsoft Microsoft Exchange Server Subscription Edition RTM
Classified asCWE-1390 (Weak Authentication)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 23
MicrosoftMicrosoft Exchange Server 2019 Cumulative Update 14
MicrosoftMicrosoft Exchange Server 2019 Cumulative Update 15
MicrosoftMicrosoft Exchange Server Subscription Edition RTM
SubsystemsGeneral OT
SectorsMultiple

What to Know

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

What to Do

Monitor Microsoft's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-96940
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-96940