AI and data stack advisories

Severe, 6 weeks2973Projects319

2973 severe, 6 weeks · 319 projects

MicrosoftCVE-2026-96940

Microsoft Exchange Server: privilege escalation

Microsoft

CVE-2026-96940 · Published Oct 2, 2026 · updated Oct 6, 2026

High8.8
Fix: upgrade to 15.01.2507.075 or later (4 fixed versions below)
Microsoft advisory

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

Affected versions

PackageAffectedFixed in
Microsoft Exchange Server 2016 Cumulative Update 23
Product
>= 15.01.0.0, < 15.01.2507.07515.01.2507.075
Microsoft Exchange Server 2019 Cumulative Update 14
Product
>= 15.02.0.0, < 15.02.1544.04815.02.1544.048
Microsoft Exchange Server 2019 Cumulative Update 15
Product
>= 15.02.0.0, < 15.02.1748.05315.02.1748.053
Microsoft Exchange Server Subscription Edition RTM
Product
>= 15.02.0.0, < 15.02.2562.05315.02.2562.053
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-1390

More Microsoft advisories

All Microsoft
Advisory
Microsoft Office Outlook: integer overflow
High7.5Sep 25
Microsoft 365 Apps for Enterprise: remote code execution
High8.8Sep 23
Microsoft Edge (Chromium-based): use after free
High8.1Sep 18
Microsoft Azure HorizonDB: improper authorization
Critical9.9Sep 18
Microsoft 365 Copilot: insecure permissions
High7.7Sep 18
Microsoft Azure Portal: cross-site scripting
High8.2Sep 18