8.8
CVE-2026-96940
Trending CVE
- EPSS 0.5%
- Veröffentlicht 02.10.2026 19:06:19
- Zuletzt bearbeitet 06.10.2026 15:05:34
- Erkennungen
Microsoft Exchange Server Elevation of Privilege Vulnerability
Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerMicrosoft
≫
Produkt
Microsoft Exchange Server 2016 Cumulative Update 23
Version
15.01.0.0
Version <
15.01.2507.075
Status
affected
HerstellerMicrosoft
≫
Produkt
Microsoft Exchange Server 2019 Cumulative Update 14
Version
15.02.0.0
Version <
15.02.1544.048
Status
affected
HerstellerMicrosoft
≫
Produkt
Microsoft Exchange Server 2019 Cumulative Update 15
Version
15.02.0.0
Version <
15.02.1748.053
Status
affected
HerstellerMicrosoft
≫
Produkt
Microsoft Exchange Server Subscription Edition RTM
Version
15.02.0.0
Version <
15.02.2562.053
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.5% | 0.404 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Microsoft | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-1390 Weak Authentication
The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940