CVE-2026-96940

LOWCVSS 8.8 · HIGH

Signal is active with 7 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1390

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 13 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 7 mentions on most recent observed day (2026-10-03)
  • 13 total mentions across 2 days

Deep dive

Activity timeline13 mentions / 2d
02457Mentions · 2026-10-02: 6Mentions · 2026-10-03: 710-0210-03
Referenced assets9 URLs
Full discourse13 posts
  • connect24h@connect24h

    これ、オンプレはまずいやつでは? Exchange担当が欲しいのは、CVE番号より自社への影響だ。番号だけ渡されても、判断する側は困る。 Exchange ServerのCVE-2026-96940。識別子は確認できるが、提示された本文には対象バージョンや攻撃条件の記載がない。私が気になるのは、権限昇格の入口にどんな権限が必要なのか。 リンク先で読みたいのは、影響を受ける製品・バージョンと攻撃成立の前提条件。この対応関係が、自社の構成と照らす材料になる。「認証後」の一言で安心する前に、その認証は誰のアカウントで通るのか。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940

    010723.0K
    7.9K followersView on X
  • Hakan Uzuner@hakanuzuner

    Microsoft, Exchange Server için CVE-2026-96940 numaralı yeni bir güvenlik açığına yönelik düzeltmeyi yayımladı. Düzeltme, Eylül 2026 Exchange Server güvenlik güncellemelerinin V2 sürümüne eklendi. Buradaki önemli noktalardan biri, Microsoft’un bu güncellemeyi normal güvenlik güncelleme takvimini beklemeden yayımlamış olması. Microsoft’un verdiği bilgiye göre güvenlik açığı şirket içinde tespit edildi ve şu an için açığın aktif olarak kullanıldığına dair bilinen bir saldırı bulunmuyor. Buna rağmen Exchange yöneticilerinin güncellemeyi mümkün olan en kısa sürede değerlendirmesi öneriliyor. Güncelleme Exchange Server Subscription Edition için doğrudan sunulurken, Exchange Server 2019 CU14/CU15 ve Exchange Server 2016 CU23 kullanan ortamlar için durum biraz farklı. Exchange Server 2016 ve 2019 artık destek dışında olduğu için bu sistemlerin güncellemeyi alabilmesi Period 2 ESU programına dahil olmalarına bağlı. Özellikle hala Exchange Server 2016 veya 2019 kullanan kurumların burada sadece CVE-2026-96940’a odaklanmaması gerekiyor. Asıl kontrol edilmesi gereken konu, ortamda çalışan Exchange sürümü ve CU seviyesinin ne olduğu, ESU kapsamının bulunup bulunmadığı ve son güvenlik güncellemelerinin gerçekten uygulanıp uygulanmadığı. Exchange Online tarafında ise kullanıcıların ayrıca bir işlem yapması gerekmiyor. Microsoft’un bulut servisleri gerekli korumaları kendi altyapısında uyguluyor. Ancak hibrit yapılarda şirket içerisinde Exchange Server veya Exchange Management Tools kurulu sistemler bulunuyorsa bunların ayrıca kontrol edilmesi gerekiyor. Eylül ayına ait V1 güvenlik güncellemesini daha önce kurmuş olanların V1’i kaldırmasına gerek yok. V2 doğrudan mevcut sistem üzerine kurulabiliyor. V1’i hiç kurmamış sistemlerde de önce V1’i yüklemek gerekmiyor; doğrudan V2 sürümüne geçilebiliyor. Ben özellikle Exchange ortamlarında güncelleme öncesinde Microsoft Exchange Health Checker çalıştırılmasını öneriyorum. Böylece sunucuların Exchange sürümü, CU/SU seviyesi ve bilinen yapılandırma sorunları güncellemeden önce görülebilir. Ardından ortama uygun V2 güvenlik güncellemesi uygulanmalı, sunucular yeniden başlatılmalı ve Exchange servisleri ile temel mail akışı kontrolleri yapılmalı. Bir diğer önemli nokta da Exchange Management Tools kurulu yönetim makineleri. Sadece Exchange sunucularını güncellemek yeterli değil; Microsoft güncellemenin Exchange Management Tools bulunan sistemlere de uygulanmasını öneriyor. CVE-2026-96940 için şu an bilinen aktif bir istismar bulunmaması güncellemenin ertelenmesi gerektiği anlamına gelmiyor. Özellikle internete servis veren Exchange sistemlerinde güvenlik güncellemelerini mümkün olduğunca kısa sürede değerlendirmek ve mevcut Exchange sürümünün destek durumunu kontrol etmek önemli. Microsoft’un CVE-2026-96940 için yayımladığı güvenlik duyurusuna MSRC Security Update Guide üzerinden ulaşabilirsiniz. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940

    02052703
    7.4K followersView on X
  • The Dustin Childs@dustin_childs

    #Microsoft released an out-of-band Exchange patch today. Not listed as under active attack, but exploitation is more likely. Sorry Exchange admin - your work continues. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940

    030411.2K
    2.4K followersView on X
  • Cybermerge@cybermergemedia

    Exchange on-prem? Microsoft pushed a V2 of September's update today, early, to add CVE-2026-96940: any valid login can escalate privileges. Found internally and not exploited, but rated more likely. 2016 and 2019 only get it via Period 2 ESU, which runs through October.

    2001066
    56 followersView on X
  • Andres Bohren 🇨🇭@andresbohren

    🚨New #ExchangeServer SE SU10 V2 has been released out of band - V2 release is an addition of CVE-2026-96940 https://tinyurl.com/mry232bw https://t.co/cReI6GbGYj

    10010159
    2.1K followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    Microsoft's September 2026 V2 Exchange Server security updates add CVE-2026-96940 for Exchange SE, 2019 and 2016. Install them now. #Microsoft #ExchangeServer #ExchangeSE #CVE202696940 #SecurityUpdate #PatchManagement #ESU https://securityonline.info/exchange-server-security-updates-september-2026-v2/

    10010325
    13.0K followersView on X
  • Günter Born@etguenni

    Es gibt mehrere #Sicherheits #Updates für #Microsoft #Exchange #Server, die gleich mehrere Schwachstellen, u.a. die Elevation of Privilege-Schwachstelle #CVE-2026-96940 schließen. https://borncity.com/blog/2026/10/02/exchange-server-sicherheits-updates-vom-2-10-2026-schliessen-cve-2026-96940/

    10010304
    2.8K followersView on X
  • Michel de Rooij@mderooij

    PSA: Exchange Server V2 Security Updates for September were published, additionally addressing CVE-2026-96940 https://eightwone.com/2026/10/03/v2-security-updates-exchange-2016-se-sep2026/ #MSExchange

    10000134
    4.5K followersView on X
  • Windows Forum@windowsforum

    🔐 Exchange Server has an 8.8 privilege-escalation flaw: a low-privilege attacker can climb the ladder over the network. “Important” is Microsoft-speak for patch your on-prem servers. https://windowsforum.com/news/cve-2026-96940-microsoft-exchange-server-elevation-of-privilege-vulnerability.447034/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #MicrosoftSecurity #Msrc #Cve202696940 https://t.co/jnhKiPSPOb

    1000095
    1.4K followersView on X
  • Cybermerge@cybermergemedia

    Fixed builds to check after install: SE 15.2.2562.53, 2019 CU15 15.2.1748.53, CU14 15.2.1544.48, 2016 CU23 15.1.2507.75. Patch the Management Tools boxes and hybrid management servers too. Exchange Team: https://techcommunity.microsoft.com/blog/exchange/released-september-2026-v2-exchange-server-security-updates/4561718 MSRC: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940

    0000059
    56 followersView on X
  • NEXSIGHT@NEXSIGHTNEWS

    MicrosoftがExchange Serverの9月更新を再発行、新たな権限昇格の脆弱性CVE-2026-96940を追加 — CVSS 8.8、早期適用を推奨 https://cyber.nexsight.co/articles/2026/10/03/exchange-server-sept-2026-v2-su-cve-2026-96940-2026-10-03/

    0000040
    76 followersView on X
  • Severity Daily@severitydaily

    Microsoft (@msftsecresponse) shipped an out-of-band Exchange update Friday: one mailbox user can read everyone else's mail. Its own Exchange team blog never announced it. No exploitation reported. https://severitydaily.com/microsoft-exchange-cve-2026-96940-out-of-band-version-2-su-no-blog-post/

    0000044
    29 followersView on X
  • Günter Born@etguenni

    I'm answering myself: The security update is (hopefully) closing CVE-2026-96940 https://borncity.com/blog/2026/10/02/exchange-server-sicherheits-updates-vom-2-10-2026-schliessen-cve-2026-96940/

    0000087
    2.8K followersView on X

Explore more