Microsoft Security Updates - October 2026
Roundup of Microsoft security advisories published in October 2026.
CVE search metadata
CVE search record: CVE-2026-96940. Severity: high. CVSS: 8.8. EPSS: 0.50%. KEV: no. Product: Exchange Server. Brief: Microsoft Security Updates - October 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-10-microsoft-security-updates/
CVE search record: CVE-2026-69435. Severity: critical. CVSS: 9.6. KEV: no. Product: Azure SRE Agent. Brief: Microsoft Security Updates - October 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-10-microsoft-security-updates/
CVE search record: CVE-2026-77900. Severity: critical. CVSS: 9.8. KEV: no. Product: Azure App Service. Brief: Microsoft Security Updates - October 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-10-microsoft-security-updates/
CVE search record: CVE-2026-88131. Severity: critical. CVSS: 9.8. KEV: no. Product: Dataverse. Brief: Microsoft Security Updates - October 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-10-microsoft-security-updates/
CVE search record: CVE-2026-94510. Severity: critical. CVSS: 9.9. KEV: no. Product: Bookings. Brief: Microsoft Security Updates - October 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-10-microsoft-security-updates/
CVE search record: CVE-2026-96207. Severity: critical. CVSS: 10.0. KEV: no. Product: Partner Center. Brief: Microsoft Security Updates - October 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-10-microsoft-security-updates/
CVE search record: CVE-2026-83943. Severity: high. CVSS: 8.7. KEV: no. Brief: Microsoft Security Updates - October 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-10-microsoft-security-updates/
CVE search record: CVE-2026-83947. Severity: high. CVSS: 7.7. KEV: no. Brief: Microsoft Security Updates - October 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-10-microsoft-security-updates/
What's new
This roundup covers 7 Microsoft security vulnerabilities. CVSS base scores range from 8.8 to 10.0. None are reported as actively exploited at the time of release. The issues affect Azure API Center, Azure App Service, Azure SRE Agent, Bookings, Dataverse, Exchange Server, Partner Center.
Summary
| CVE | Product | Severity | CVSS | EPSS | KEV | Source |
|---|---|---|---|---|---|---|
| CVE-2026-96940 | Exchange Server | High | 8.8 | 0.50% | no | MSRC (authoritative) |
| CVE-2026-69435 | Azure SRE Agent | Critical | 9.6 | no | NVD (authoritative) | |
| CVE-2026-77900 | Azure App Service | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-88131 | Dataverse | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-94510 | Bookings | Critical | 9.9 | no | NVD (authoritative) | |
| CVE-2026-96207 | Partner Center | Critical | 10.0 | no | NVD (authoritative) | |
| CVE-2026-83943 | Azure API Center | no | NVD (authoritative) |
CVE-2026-96940
Microsoft Exchange Server contains a vulnerability due to weak authorization that allows an authenticated attacker to elevate their privileges over the network.
Affected products:
- Exchange Server
Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940
CVE-2026-69435
CVE-2026-69435 is a vulnerability in the Microsoft Azure SRE Agent caused by missing authorization checks. This flaw allows an authenticated attacker to perform unauthorized actions and escalate privileges over the network.
Affected products:
- Azure SRE Agent
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-69435
CVE-2026-77900
A vulnerability in Microsoft Azure App Service allows an unauthorized remote attacker to execute arbitrary code due to missing authentication for a critical function. This flaw carries a high CVSS base score of 9.8 and facilitates RCE over a network without requiring prior authentication.
Affected products:
- Azure App Service
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-77900
CVE-2026-88131
CVE-2026-88131 is a critical vulnerability in Microsoft Dataverse involving insecure deserialization of untrusted data, which allows an unauthenticated remote attacker to achieve remote code execution (RCE) over a network.
Affected products:
- Dataverse
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-88131
CVE-2026-94510
Microsoft Bookings contains an authorization bypass vulnerability (CVE-2026-94510) caused by a user-controlled key, which allows an unauthenticated attacker to perform privilege escalation over a network. The vulnerability carries a high CVSS base score of 9.9, indicating critical severity.
Affected products:
- Bookings
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-94510
CVE-2026-96207
CVE-2026-96207 describes a vulnerability in Microsoft Partner Center involving improper certificate validation. This flaw allows an unauthorized, network-adjacent attacker to perform privilege escalation within the platform.
Affected products:
- Partner Center
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-96207
CVE-2026-83943
CVE-2026-83943 is an information exposure vulnerability in Microsoft Azure API Center that allows an unauthorized attacker to access sensitive information over a network. The vulnerability has a CVSS v3.1 base score of 8.7, indicating a high risk of unauthorized data disclosure.
Affected products:
- Azure API Center