CVE-2026-69361 Microsoft Exchange Server Spoofing Vulnerability
6.5
Analysis on rafaelpfister.ch
- Article · October 7, 2026 September 2026 Exchange security updates: nine vulnerabilities, wrapper issue fixed, v2 released The September SU addresses nine vulnerabilities in Exchange SE and 2019 (eight in Exchange 2016), including a spoofing vulnerability with CVSS 9.3, and fixes the wrapper issue in hybrid environments. Version 2 followed on October 2 with an additional CVE; there are also three known issues with workarounds and a SettingOverride that should now be removed.
- Article · October 7, 2026 Exchange Security Update September 2026 v2: Early Fix for CVE-2026-96940 On October 2, 2026, Microsoft released version 2 of the September SUs for Exchange SE, 2019, and 2016. It additionally closes CVE-2026-96940, an elevation-of-privilege vulnerability with CVSS 8.8 and an “Exploitation More Likely” assessment. Microsoft recommends installing v2 as soon as possible, including on servers with the first September SU.
Vendor description
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. Reference data
- Vendor
- Microsoft
- Affected products
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Update 14
- Microsoft Exchange Server 2019 Cumulative Update 15
- Microsoft Exchange Server Subscription Edition RTM
- CVSS 3.1
- 6.5 (MEDIUM)
- Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C- Weakness type
- CWE-918: Server-Side Request Forgery
- Published
- September 8, 2026