AI analysis
CVE-2026-96940 is a weak-authorization flaw in Microsoft Exchange Server (CWE-1390) that lets an already authenticated attacker elevate privileges over the network. It is remotely reachable with low attack complexity and no user interaction, and the CVSS 3.1 vector rates confidentiality, integrity, and availability impact as high while keeping scope unchanged. A low-privileged authenticated user can therefore gain high-impact control of the affected Exchange component. Affected version ranges were not included in the provided data, so any on-premises Exchange Server deployment should be checked against Microsoft's advisory. It is not listed in CISA KEV, and no public proof-of-concept is known.
What to do: Check Microsoft's advisory for CVE-2026-96940 and install the Exchange Server security update for every build it lists as affected. Until that update is applied, limit network access to Exchange to trusted users and networks, and review privileged role assignments and authentication logs for unexpected elevation.
Affected
| Microsoft Exchange Server | — |
Estimated exposure
largeTens of thousands of internet-exposed on-premises Exchange servers potentially in scope; vulnerable subset unknown — On-premises Microsoft Exchange is still widely deployed; public internet scans have commonly shown on the order of tens of thousands of reachable servers, and mailbox counts are far larger, but the vulnerable subset cannot be counted…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.