CyberICT

CVE-2026-96940

Microsoft · Published October 2, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Microsoft Exchange Server Elevation of Privilege Vulnerability. Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

Affected Products

  • Microsoft Exchange Server 2019 Cumulative Update 14
  • Microsoft Exchange Server 2016 Cumulative Update 23
  • Microsoft Exchange Server Subscription Edition RTM
  • Microsoft Exchange Server 2019 Cumulative Update 15

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C