# Microsoft patches Exchange privilege escalation flaw

Published: 2026-10-06 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/4b8ed47e-64b0-56bc-bab1-ca7f0db3d09d/microsoft-patches-exchange-privilege-escalation-flaw

> An out-of-band Microsoft patch fixes a weak-authorization flaw in on-premise Exchange Server allowing authenticated privilege escalation.

NCSC-NL issued an advisory for CVE-2026-96940, a weak authentication/authorization vulnerability in Microsoft Exchange Server, patched out-of-band ahead of Microsoft's regular October update cycle. The flaw allows an authenticated attacker to remotely escalate privileges, potentially enabling unauthorized administrative actions within an affected Exchange Server environment. The vulnerability carries a CVSS v3 score of 8.8.

Exchange Online customers require no action, as Microsoft has centrally rolled out the fix for its cloud service. However, organizations running Exchange on-premise must apply the released updates themselves. No in-the-wild exploitation is mentioned in the advisory. Defenders operating on-premise Exchange Server should prioritize applying the patch and review authentication/authorization logs for signs of privilege escalation attempts by authenticated users.

## Mentioned in this report

- Vulnerabilities: CVE-2026-96940

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0401.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4b8ed47e-64b0-56bc-bab1-ca7f0db3d09d/microsoft-patches-exchange-privilege-escalation-flaw.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
