Threat Advisory

Microsoft Exchange Server Flaw Allows Unauthorized Access

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A remote code execution vulnerability, identified as CVE-2026-96940 with a CVSS score of 9.8, can be exploited by sending specially crafted emails to users, allowing an attacker to execute arbitrary code on the server. This flaw affects Exchange Server Subscription Edition (SE) RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23, but only organizations enrolled in the Period 2 Extended Security Update (ESU) program can download these fixes for older versions. Exchange Online is already protected; however, hybrid customers need to install the update on their Exchange servers, even if they are used solely for management purposes, and also patch every workstation that runs the Exchange Management Tools. The business impact of this vulnerability is significant, as it allows an attacker to execute arbitrary code on the server, potentially leading to data breaches or other security incidents.

RECOMMENDATION:

We recommend you to update Exchange Server to the latest available version.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A remote code execution vulnerability, identified as CVE-2026-96940 with a CVSS score of 9.8, can be exploited by sending specially crafted emails to users, allowing an attacker to execute arbitrary code on the server. This flaw affects Exchange Server Subscription Edition (SE) RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23, but only organizations enrolled in the Period 2 Extended Security Update (ESU) program can download these fixes for older versions. Exchange Online is already protected; however, hybrid customers need to install the update on their Exchange servers, even if they are used solely for management purposes, and also patch every workstation that runs the Exchange Management Tools. The business impact of this vulnerability is significant, as it allows an attacker to execute arbitrary code on the server, potentially leading to data breaches or other security incidents.

RECOMMENDATION:

We recommend you to update Exchange Server to the latest available version.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu