CVE-2026-96940 Microsoft Exchange Server Elevation of Privilege Vulnerability
8.8
Analyse auf rafaelpfister.ch
- Artikel · 7. Oktober 2026 Exchange-Sicherheitsupdates vom September 2026: neun Schwachstellen, Wrapper-Problem behoben, v2 nachgeschoben Das September-SU schliesst neun Schwachstellen in Exchange SE und 2019 (acht in Exchange 2016), darunter eine Spoofing-Lücke mit CVSS 9.3, und behebt das Wrapper-Problem in Hybrid-Umgebungen. Am 2. Oktober folgte eine v2 mit einer zusätzlichen CVE; dazu kommen drei Known Issues mit Workarounds und ein SettingOverride, der jetzt entfernt werden soll.
- Artikel · 7. Oktober 2026 Exchange-Sicherheitsupdate September 2026 v2: vorgezogener Fix für CVE-2026-96940 Am 2. Oktober 2026 hat Microsoft eine Version 2 der September-SUs für Exchange SE, 2019 und 2016 veröffentlicht. Sie schliesst zusätzlich CVE-2026-96940, eine Elevation-of-Privilege-Lücke mit CVSS 8.8 und der Einschätzung «Exploitation More Likely». Microsoft empfiehlt, v2 so bald wie möglich zu installieren, auch auf Servern mit dem ersten September-SU.
Beschreibung des Herstellers (englisch)
An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests. An attacker who successfully exploited this vulnerability could perform script/content injection attacks and attempt to trick the user into disclosing sensitive information.
To exploit the vulnerability, an attacker could send a specially crafted email message containing a malicious link to a user. Alternatively, an attacker could use a chat client to social engineer a user into clicking the malicious link.
The security update addresses the vulnerability by correcting how Microsoft Exchange validates web requests.
Note: In order to exploit this vulnerability, a user must click a maliciously crafted link from an attacker. Stammdaten
- Hersteller
- Microsoft
- Betroffene Produkte
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Update 14
- Microsoft Exchange Server 2019 Cumulative Update 15
- Microsoft Exchange Server Subscription Edition RTM
- CVSS 3.1
- 8.8 (HIGH)
- Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C- Schwachstellentyp
- CWE-1390: Weak Authentication
- Veröffentlicht
- 2. Oktober 2026