Apply the out-of-band security updates released by Microsoft for CVE-2026-96940. Administrators should consult official Microsoft security advisories for deployment guidance and verify the update applicability for their specific Exchange Server version.
Quick answers
What is CVE-2026-96940?
Apply the out-of-band security updates released by Microsoft for CVE-2026-96940. Administrators should consult official Microsoft security advisories for deployment guidance and verify the update applicability for their specific Exchange Server version.
How severe is CVE-2026-96940?
high, CVSS 8.8
Is CVE-2026-96940 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-96940 be mitigated?
Apply the out-of-band security updates released by Microsoft for CVE-2026-96940. Administrators should consult official Microsoft security advisories for deployment guidance and verify the update applicability for their specific Exchange Server version.
CVSS
8.8
Vendor
Microsoft
Published
Oct 6, 2026 · 01:56
Patch
Unknown / not confirmed
Affected products
Microsoft Exchange Server
Mitigation
Apply the out-of-band security updates released by Microsoft for CVE-2026-96940. Administrators should consult official Microsoft security advisories for deployment guidance and verify the update applicability for their specific Exchange Server version.
Microsoft has released out-of-band security updates to address CVE-2026-96940, a high-severity vulnerability in Microsoft Exchange Server rated 8.8 on the CVSS scale. The flaw involves weak authorization mechanisms that could allow an authenticated attacker to elevate privileges and access other users' mailboxes. Administrators are urged to apply the updates promptly.