CVE-2026-96940High· 8.8▾ TwilightWeak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-73025Critical· 9.8Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-77483High· 8.8Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-62895High· 8.8Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62910High· 7.2Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2026-62912Medium· 6.5Microsoft Exchange Server Denial of Service Vulnerability
CVE-2026-62913High· 8.8Microsoft Exchange Server Remote Code Execution Vulnerability