Skip to main content

Microsoft Exchange Server Elevation of Privilege Flaw Is October's Only Patch Tuesday Fix (CVE-2026-96940)

Scope: Microsoft Exchange Server, all supported on-premises versions

Severity: Amber

October's Patch Tuesday was unusually small, one single fix, and it happens to be for Exchange Server. CVE-2026-96940 is an elevation of privilege flaw rated CVSS 8.8, and Microsoft's own exploitability assessment calls it "more likely" to be exploited, which is the label Microsoft reserves for flaws it expects attackers to weaponise rather than ignore. No public exploitation has been confirmed yet. What makes a flaw like this worth taking seriously regardless of the small patch count is where it sits, Exchange Server holds every email that passes through an organisation, and an elevation of privilege bug there is usually the second step in an attack chain that started somewhere else, a phished account or a stolen set of credentials, turned into full control of the mail system. Organisations running on-premises Exchange Server must apply the October 2026 cumulative security update now.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.