CVE-2026-96940HighCVSS 8.8
Microsoft Exchange Server Elevation of Privilege Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
🎯 Affected products4
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Update 14
- Microsoft Exchange Server 2019 Cumulative Update 15
- Microsoft Exchange Server Subscription Edition RTM
✅ Remediation
KB5129957 (Security Update) — fixed build 15.02.1544.048 KB5129958 (Security Update) — fixed build 15.01.2507.075 KB5129955 (Security Update) — fixed build 15.02.2562.053 KB5129956 (Security Update) — fixed build 15.02.1748.053
🔗 References (6)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940
- referencehttps://support.microsoft.com/help/5129957
- referencehttps://support.microsoft.com/help/5129958
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5129955
- referencehttps://support.microsoft.com/help/5129955
- referencehttps://support.microsoft.com/help/5129956