Vulnerability record

CVE-2026-96940

Severity: HighExploitation: No known exploitation

Patch status

No official fix confirmed yet

Until a fix ships, follow the vendor's mitigations, limit exposure of affected systems, and watch this record for a patch.

Description

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.

Intelligence timeline

Developments from the last 30 days, newest first.

  1. CVSS scoredUpdate

    CVE-2026-96940 scored CVSS 8.8

    Basis: NIST National Vulnerability Database

Coverage

We have not published a story about this vulnerability yet.

References