Microsoft security advisory (AV26-1001)
Canada's Cyber Centre urges patches for Exchange elevation-of-privilege flaw CVE-2026-96940.
The Canadian Centre for Cyber Security issued advisory AV26-1001 on October 5, 2026, for a Microsoft Exchange Server elevation-of-privilege vulnerability, CVE-2026-96940. Affected versions include Exchange Server 2016 CU23 before 15.01.2507.075, Exchange Server 2019 CU14 before 15.02.1544.048, CU15 before 15.02.1748.053, and Subscription Edition RTM before 15.02.2562.053. Administrators are told to review Microsoft's Security Update Guide and apply available updates. The advisory does not say the flaw is being exploited.
- CVE-2026-96940 is an Exchange Server elevation-of-privilege vulnerability.
- Exchange 2016, 2019, and Subscription Edition builds are listed.
- Advisory AV26-1001 directs administrators to Microsoft's update guide.
- The bulletin does not report active exploitation.
Vulnerabilities mentionedAll →
- CVE-2026-969408.8<1%Weak authorization privilege escalation in Microsoft Exchange Serverpublished · Microsoft Exchange Server PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-96940 | Weak authorization privilege escalation in Microsoft Exchange Server |
Full article95 words · extracted from cyber.gc.ca · click to collapse
Serial Number: AV26-1001
Date: October 5, 2026
As of October 2, 2026, Microsoft is affected by a vulnerability in the following products:
- Microsoft Exchange Server 2016 Cumulative Update 23
- Prior to 15.01.2507.075
- Microsoft Exchange Server 2019 Cumulative Update 14
- Prior to 15.02.1544.048
- Microsoft Exchange Server 2019 Cumulative Update 15
- Prior to 15.02.1748.053
- Microsoft Exchange Server Subscription Edition RTM
- Prior to 15.02.2562.053
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-av26-1001