CVE-2026-96940: Microsoft Exchange Server Elevation of Privilege Vulnerability

Overview

Severity
High (CVSS 8.8)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Elevation of Privilege
Exploit Status
Not Exploited
Exploitation Likelihood
More Likely
Patch Tuesday
2026-Oct
Released
2026-10-02

Description

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

FAQ

Is Exchange Online affected, and do Exchange Online customers need to take action? Microsoft has already deployed a related service-side fix to Exchange Online. Exchange Online customers do not need to take any action to receive the fix. Customers using affected on-premises Microsoft Exchange Server products should install the applicable security updates listed in the Security Updates table. Where can I find more information? Please see the Exchange blog for more information. What privileges could be gained by an attacker who successfully exploited this vulnerability? An authenticated attacker who successfully exploited this vulnerability could gain unauthorized access to other users' mailboxes within the same organization and read email messages and attachments. The vulnerability does not allow access across tenant boundaries.

Affected Products (4)

ESU

  • Microsoft Exchange Server 2019 Cumulative Update 14
  • Microsoft Exchange Server 2016 Cumulative Update 23
  • Microsoft Exchange Server 2019 Cumulative Update 15

Server Software

  • Microsoft Exchange Server Subscription Edition RTM

Security Updates (1)

Acknowledgments

Jan Mitchell from Microsoft

Revision History

  • 2026-10-02: Information published.