122/122 sources · synced 20:24 UTC Customize Public mode

Microsoft Exchange Server Elevation of Privilege Vulnerability

Assessment

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

Severity
Important
CVSS base score
8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Impact
Elevation of Privilege
EPSS, next 30 days
Not scored yet
Public exploit code
No Nuclei template lists it
Exploitability
Exploitation More Likely
Publicly disclosed
No
Customer action
Required: apply the update
Component
Microsoft Exchange Server
Weakness
CWE-1390: Weak Authentication
Issued by
Microsoft
Published
2 Oct 2026 · October 2026
Last revised
2 Oct 2026

Updates that fix it

4 KBs
KBTypeRestartApplies toOther CVEs
KB5129955 Security Update — Microsoft Exchange Server Subscription Edition RTM All CVEs in KB5129955
KB5129956 Security Update — Microsoft Exchange Server 2019 Cumulative Update 15 All CVEs in KB5129956
KB5129957 Security Update — Microsoft Exchange Server 2019 Cumulative Update 14 All CVEs in KB5129957
KB5129958 Security Update — Microsoft Exchange Server 2016 Cumulative Update 23 All CVEs in KB5129958

Affected products

ESU, Server Software
ChangeIntel

An IT change radar: releases, security, known issues, retirements, and service status from 122 public sources. Every item links to its original page; dates and statuses can change after they are read.

Sources read 2 Oct 20:24 UTC · 122 of 122 readable