Heise.De Microsoft Exchange CVE-2026-96940 Update Released for Privilege Escalation Vulnerability
Article Content
- •CVE-2026-96940 has a CVSS score of 8.8, indicating a high severity level.
- •The vulnerability allows authenticated attackers to escalate privileges and access other users' mailboxes.
- •Microsoft recommends immediate installation of updates on all affected on-premises Exchange servers.
Microsoft has released an update for Exchange Server to address CVE-2026-96940, a significant privilege escalation vulnerability with a CVSS score of 8.8. The flaw allows authenticated attackers to elevate their privileges over the network, potentially accessing other users' mailboxes. This vulnerability affects on-premises versions of Exchange Server, including SE RTM, 2019 CU14/CU15, and 2016 CU23, which require updates as part of the Extended Security Update Program. Microsoft has stated that they are unaware of any of this vulnerability. The update was made available over the weekend, and administrators are urged to apply it promptly to mitigate risks. Additionally, the update may cause some side effects, such as HTTP 500 errors in calendar applications.
Ask AI about this cluster
Answers cite the sources they use
More articles in this cluster (2)
Following this threat?
Track CVE-2026-96940 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of Exchange are affected?
Is there any confirmed exploitation of this vulnerability?
What should administrators do now?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…