Skip to content

Release roundup

Microsoft Patch Tuesday, October 2026: Exchange Server elevation of privilege fix leads a one-CVE release

High 8.8 Vendor: Microsoft 1 CVEs in scope Published

Microsoft's October 2026 Patch Tuesday lists one CVE in scope: CVE-2026-96940, an Exchange Server elevation of privilege vulnerability rated high at CVSS 8.8. It is not in CISA KEV and not reported exploited. Apply the matching Exchange security update.

The release at a glance

Microsoft's October 2026 Patch Tuesday release note lists one CVE in scope for this roundup: CVE-2026-96940, a Microsoft Exchange Server elevation of privilege vulnerability. The record was published on 2 October 2026. Microsoft rates the vulnerability Important; the CVSS 3.1 base score is 8.8, with a severity of high. The release's severity count is one high. Affected products are Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server 2019 Cumulative Update 15, and Microsoft Exchange Server Subscription Edition RTM. The CVE is not present in CISA's Known Exploited Vulnerabilities catalogue, and the CVE record does not state that it has been exploited in the wild.

What matters most

CVE-2026-96940 is the CVE to assess first in this release. In Microsoft's advisory for CVE-2026-96940, the flaw is described as weak authorization in Microsoft Exchange Server, tracked as CWE-1390. An authenticated attacker with low privileges can trigger the elevation of privilege over a network without user interaction; the CVSS vector is AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C. Successful exploitation can give high impact to confidentiality, integrity and availability, but the vector requires low rather than no privileges, so this is not an unauthenticated flaw.

The affected version ranges are:

  • Microsoft Exchange Server 2016 Cumulative Update 23: 15.01.0.0 to before 15.01.2507.075
  • Microsoft Exchange Server 2019 Cumulative Update 14: 15.02.0.0 to before 15.02.1544.048
  • Microsoft Exchange Server 2019 Cumulative Update 15: 15.02.0.0 to before 15.02.1748.053
  • Microsoft Exchange Server Subscription Edition RTM: 15.02.0.0 to before 15.02.2562.053

The SSVC decision in the CVE record shows exploitation as none, automatable as no, and technical impact as total. No EPSS score is listed in the CVE record.

Patch in this order

The release contains one CVE in scope, and no CVE in this release is listed in CISA KEV or marked as exploited. The CVE record does not state a workaround, so applying the update is the primary action.

  1. Establish which Exchange Server branch and build you run. The affected builds are listed above.
  2. Apply the matching security update to every affected server:
  • Microsoft Exchange Server 2016 CU23: 15.01.2507.075 (KB5129958)
  • Microsoft Exchange Server 2019 CU14: 15.02.1544.048 (KB5129957)
  • Microsoft Exchange Server 2019 CU15: 15.02.1748.053 (KB5129956)
  • Microsoft Exchange Server Subscription Edition RTM: 15.02.2562.053 (KB5129955)
  1. Sequence patching so that Exchange servers reachable from the network are updated first; the CVSS vector shows a network attack vector with low privileges required, and high impact.
  2. After installation, confirm the build number matches the fixed version for the branch. No additional CVEs are present in this release.

Beyond the patch

A one-CVE Exchange release is a decision that should be quick to make: confirm the branch, apply the fixed build, and verify. Managed Detection & Response is suited to watching for the privilege-elevation and credential-abuse patterns that can follow an Exchange compromise, and Supply Chain Defense & Third-Party Risk turns supplier patch cadence into a measured exposure window in your vendor inventory. For a Microsoft-dependent estate, that makes next month's equivalent release a repeatable process rather than a fresh assessment.

Every CVE in this release

CVEProductSeverity
CVE-2026-96940Microsoft Exchange Server 2016 Cumulative Update 23High 8.8

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.