8.8

CVE-2026-96940

Medienbericht

Microsoft Exchange Server Elevation of Privilege Vulnerability

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerMicrosoft
≫
Produkt Microsoft Exchange Server 2016 Cumulative Update 23
Version 15.01.0.0
Version < 15.01.2507.075
Status affected
HerstellerMicrosoft
≫
Produkt Microsoft Exchange Server 2019 Cumulative Update 14
Version 15.02.0.0
Version < 15.02.1544.048
Status affected
HerstellerMicrosoft
≫
Produkt Microsoft Exchange Server 2019 Cumulative Update 15
Version 15.02.0.0
Version < 15.02.1748.053
Status affected
HerstellerMicrosoft
≫
Produkt Microsoft Exchange Server Subscription Edition RTM
Version 15.02.0.0
Version < 15.02.2562.053
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.5% 0.404
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Microsoft 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-1390 Weak Authentication

The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
05.10.2026 19:28
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
05.10.2026 08:43
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940