CVE-2026-96940 Microsoft Exchange Server Elevation of Privilege Vulnerability
8.8
Analisi su rafaelpfister.ch
- Articolo · 7 ottobre 2026 Aggiornamenti di sicurezza di Exchange di settembre 2026: nove vulnerabilità, risolto il problema dei wrapper, rilasciata la v2 L'aggiornamento di sicurezza di settembre chiude nove vulnerabilità in Exchange SE e 2019 (otto in Exchange 2016), tra cui una falla di spoofing con CVSS 9.3, e risolve il problema dei wrapper negli ambienti ibridi. Il 2 ottobre è seguita una v2 con un'ulteriore CVE; si aggiungono tre problemi noti con workaround e un SettingOverride che ora deve essere rimosso.
- Articolo · 7 ottobre 2026 Aggiornamento di sicurezza di Exchange settembre 2026 v2: correzione anticipata per CVE-2026-96940 Il 2 ottobre 2026 Microsoft ha rilasciato una versione 2 degli aggiornamenti di sicurezza di settembre per Exchange SE, 2019 e 2016. Chiude inoltre CVE-2026-96940, una vulnerabilità di elevazione dei privilegi con CVSS 8.8 e valutazione «Exploitation More Likely». Microsoft raccomanda di installare v2 il prima possibile, anche sui server con il primo SU di settembre.
Descrizione del produttore (in inglese)
An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests. An attacker who successfully exploited this vulnerability could perform script/content injection attacks and attempt to trick the user into disclosing sensitive information.
To exploit the vulnerability, an attacker could send a specially crafted email message containing a malicious link to a user. Alternatively, an attacker could use a chat client to social engineer a user into clicking the malicious link.
The security update addresses the vulnerability by correcting how Microsoft Exchange validates web requests.
Note: In order to exploit this vulnerability, a user must click a maliciously crafted link from an attacker. Dati di riferimento
- Produttore
- Microsoft
- Prodotti interessati
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Update 14
- Microsoft Exchange Server 2019 Cumulative Update 15
- Microsoft Exchange Server Subscription Edition RTM
- CVSS 3.1
- 8.8 (HIGH)
- Vettore
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C- Tipo di debolezza
- CWE-1390: Weak Authentication
- Pubblicata
- 2 ottobre 2026