AI description
CVE-2026-96940 is an elevation of privilege vulnerability in Microsoft Exchange Server stemming from weak authorization mechanisms. An authenticated attacker can exploit this flaw over a network to elevate their privileges without requiring any user interaction. Successful exploitation allows the attacker to access other users' mailboxes within the same organization, read email messages and attachments, modify server configurations, and disrupt service availability. The vulnerability affects on-premises deployments, including Microsoft Exchange Server 2016 Cumulative Update 23, Exchange Server 2019 Cumulative Updates 14 and 15, and Exchange Server Subscription Edition RTM. Microsoft discovered the flaw internally and reported no evidence of active exploitation or public proof-of-concept exploits. To address the issue, Microsoft released the September 2026 V2 security updates. Exchange Online customers are already protected and do not require further action.
- Description
- Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
- Source
- secure@microsoft.com
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- secure@microsoft.com
- CWE-1390
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
7
🇺🇸🚨 MICROSOFT EXCHANGE CVE-2026-96940 — IMPORTANT EOP IN SEPT 2026 V2 SU Microsoft released September 2026 V2 / October 2026 early Exchange Server security updates adding CVE-2026-96940. Per MSRC (published 2 Oct 2026): • Important elevation of privilege, CVSS 8.8,
@DailyDarkWeb
3 Oct 2026
3577 Impressions
3 Retweets
17 Likes
4 Bookmarks
0 Replies
0 Quotes
We have just added an important vulnerability affecting Microsoft Exchange Server (CVE-2026-96940) vuldb.com/vuln/413205
@vuldb
3 Oct 2026
121 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Microsoft Reissues September 2026 Exchange Server Security Updates to Add CVE-2026-96940 Critical Vulnerability Alert! Microsoft Exchange Server (SE RTM, 2019 CU14/CU15, 2016 CU23) is affected by CVE-2026-96940. 🔍 Identify Targets via ZoomEye: Search Dork: app="Microso
@zoomeyebot
3 Oct 2026
40 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
🚨New #ExchangeServer SE SU10 V2 has been released out of band - V2 release is an addition of CVE-2026-96940 https://t.co/1AQWSdvavo https://t.co/cReI6GbGYj
@andresbohren
3 Oct 2026
21 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft warns of a privilege escalation flaw in Exchange Server (CVE-2026-96940) CVE-2026-96940 Microsoft has issued an advisory for CVE-2026-96940, an authorisation weakness in Exchange Server rated CVSS 8.8 that allows an… #CVE #Microsoft #infosec https://t.co/uckLxWyBZ9
@Orbitaley
2 Oct 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes