Oct 2026: Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2026-96940 Published on October 2, 2026
Microsoft Exchange Server Elevation of Privilege Vulnerability
Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
Weakness Type
CWE-1390
Products Associated with CVE-2026-96940
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft Exchange Server 2016 Cumulative Update 23:- Version 15.01.0.0 and below 15.01.2507.075 is affected.
- Version 15.02.0.0 and below 15.02.1544.048 is affected.
- Version 15.02.0.0 and below 15.02.1748.053 is affected.
- Version 15.02.0.0 and below 15.02.2562.053 is affected.