Skip to content
Threat Feed
high threat updated

Microsoft Security Updates - October 2026

Roundup of Microsoft security advisories published in October 2026.

CVE search metadata

CVE search record: CVE-2026-96940. Severity: high. CVSS: 8.8. EPSS: 0.50%. KEV: no. Product: Exchange Server. Brief: Microsoft Security Updates - October 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-10-microsoft-security-updates/

CVE search record: CVE-2026-69435. Severity: critical. CVSS: 9.6. KEV: no. Product: Azure SRE Agent. Brief: Microsoft Security Updates - October 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-10-microsoft-security-updates/

CVE search record: CVE-2026-77900. Severity: critical. CVSS: 9.8. KEV: no. Product: Azure App Service. Brief: Microsoft Security Updates - October 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-10-microsoft-security-updates/

CVE search record: CVE-2026-88131. Severity: critical. CVSS: 9.8. KEV: no. Product: Dataverse. Brief: Microsoft Security Updates - October 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-10-microsoft-security-updates/

CVE search record: CVE-2026-94510. Severity: critical. CVSS: 9.9. KEV: no. Product: Bookings. Brief: Microsoft Security Updates - October 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-10-microsoft-security-updates/

CVE search record: CVE-2026-96207. Severity: critical. CVSS: 10.0. KEV: no. Product: Partner Center. Brief: Microsoft Security Updates - October 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-10-microsoft-security-updates/

CVE search record: CVE-2026-83943. Severity: high. CVSS: 8.7. KEV: no. Brief: Microsoft Security Updates - October 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-10-microsoft-security-updates/

CVE search record: CVE-2026-83947. Severity: high. CVSS: 7.7. KEV: no. Brief: Microsoft Security Updates - October 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-10-microsoft-security-updates/

What's new

  • 1. added CVE-2026-83943 +1 Oct 9, 00:31 via nvd
  • 2. added CVE-2026-96207 Oct 9, 00:09 via nvd
  • 3. added CVE-2026-94510 Oct 9, 00:08 via nvd
  • 4. added CVE-2026-88131 Oct 9, 00:06 via nvd
  • 5. added CVE-2026-77900 Oct 9, 00:05 via nvd

This roundup covers 7 Microsoft security vulnerabilities. CVSS base scores range from 8.8 to 10.0. None are reported as actively exploited at the time of release. The issues affect Azure API Center, Azure App Service, Azure SRE Agent, Bookings, Dataverse, Exchange Server, Partner Center.

Summary

CVEProductSeverityCVSSEPSSKEVSource
CVE-2026-96940Exchange ServerHigh8.80.50%noMSRC (authoritative)
CVE-2026-69435Azure SRE AgentCritical9.6noNVD (authoritative)
CVE-2026-77900Azure App ServiceCritical9.8noNVD (authoritative)
CVE-2026-88131DataverseCritical9.8noNVD (authoritative)
CVE-2026-94510BookingsCritical9.9noNVD (authoritative)
CVE-2026-96207Partner CenterCritical10.0noNVD (authoritative)
CVE-2026-83943Azure API CenternoNVD (authoritative)

CVE-2026-96940

Microsoft Exchange Server contains a vulnerability due to weak authorization that allows an authenticated attacker to elevate their privileges over the network.

Affected products:

  • Exchange Server

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940

CVE-2026-69435

CVE-2026-69435 is a vulnerability in the Microsoft Azure SRE Agent caused by missing authorization checks. This flaw allows an authenticated attacker to perform unauthorized actions and escalate privileges over the network.

Affected products:

  • Azure SRE Agent

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-69435

CVE-2026-77900

A vulnerability in Microsoft Azure App Service allows an unauthorized remote attacker to execute arbitrary code due to missing authentication for a critical function. This flaw carries a high CVSS base score of 9.8 and facilitates RCE over a network without requiring prior authentication.

Affected products:

  • Azure App Service

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-77900

CVE-2026-88131

CVE-2026-88131 is a critical vulnerability in Microsoft Dataverse involving insecure deserialization of untrusted data, which allows an unauthenticated remote attacker to achieve remote code execution (RCE) over a network.

Affected products:

  • Dataverse

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-88131

CVE-2026-94510

Microsoft Bookings contains an authorization bypass vulnerability (CVE-2026-94510) caused by a user-controlled key, which allows an unauthenticated attacker to perform privilege escalation over a network. The vulnerability carries a high CVSS base score of 9.9, indicating critical severity.

Affected products:

  • Bookings

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-94510

CVE-2026-96207

CVE-2026-96207 describes a vulnerability in Microsoft Partner Center involving improper certificate validation. This flaw allows an unauthorized, network-adjacent attacker to perform privilege escalation within the platform.

Affected products:

  • Partner Center

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-96207

CVE-2026-83943

CVE-2026-83943 is an information exposure vulnerability in Microsoft Azure API Center that allows an unauthorized attacker to access sensitive information over a network. The vulnerability has a CVSS v3.1 base score of 8.7, indicating a high risk of unauthorized data disclosure.

Affected products:

  • Azure API Center

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83943