Microsoft Security Response Center guidance
Install KB5129957. Install KB5129958. Install KB5129955. Install KB5129956.
Vendor-listed releases
- 15.02.1544.048
- 15.01.2507.075
- 15.02.2562.053
- 15.02.1748.053
Vulnerability intelligence
CVE-2026-96940 and is rated High severity with a CVSS score of 8.8. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Install KB5129957. Install KB5129958. Install KB5129955. Install KB5129956.
Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.