Skip to content
Microsoft Exchange CVE-2026-96940 Update Released for Privilege Escalation Vulnerability

Microsoft Exchange CVE-2026-96940 Update Released for Privilege Escalation Vulnerability

First seen 5 Oct 2026, 09:27 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 09:28 UTC
  • •CVE-2026-96940 has a CVSS score of 8.8, indicating a high severity level.
  • •The vulnerability allows authenticated attackers to escalate privileges and access other users' mailboxes.
  • •Microsoft recommends immediate installation of updates on all affected on-premises Exchange servers.

Microsoft has released an update for Exchange Server to address CVE-2026-96940, a significant privilege escalation vulnerability with a CVSS score of 8.8. The flaw allows authenticated attackers to elevate their privileges over the network, potentially accessing other users' mailboxes. This vulnerability affects on-premises versions of Exchange Server, including SE RTM, 2019 CU14/CU15, and 2016 CU23, which require updates as part of the Extended Security Update Program. Microsoft has stated that they are unaware of any of this vulnerability. The update was made available over the weekend, and administrators are urged to apply it promptly to mitigate risks. Additionally, the update may cause some side effects, such as HTTP 500 errors in calendar applications.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-02
CVE-2026-96940 published
Microsoft disclosed CVE-2026-96940, a privilege escalation vulnerability in Exchange Server.
Heise.De
2026-10-04
Microsoft releases Exchange update
An update was released to address CVE-2026-96940, requiring immediate action from admins.
Heise.De

More articles in this cluster (2)

Following this threat?

Track CVE-2026-96940 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of Exchange are affected?
The vulnerability affects Exchange SE RTM, 2019 CU14/CU15, and 2016 CU23.
Is there any confirmed exploitation of this vulnerability?
Microsoft has stated they are not aware of any active exploitation of CVE-2026-96940.
What should administrators do now?
Administrators should promptly install the update on all affected on-premises Exchange servers.