CVE-2026-96940

Summary

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

Affected Software

VendorProductVersion RangeStatus
MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 2315.01.0.0 < 15.01.2507.075affected
MicrosoftMicrosoft Exchange Server 2019 Cumulative Update 1415.02.0.0 < 15.02.1544.048affected
MicrosoftMicrosoft Exchange Server 2019 Cumulative Update 1515.02.0.0 < 15.02.1748.053affected
MicrosoftMicrosoft Exchange Server Subscription Edition RTM15.02.0.0 < 15.02.2562.053affected

Weaknesses

  • CWE-1390: CWE-1390: Weak Authentication

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References