CVE-2026-69641
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVSS
9.1
Critical
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 8, 2026 · Last modified: Sep 8, 2026 · CWE-862
Not enough EPSS history yet.
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-839427.8 HIG—
———Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally.5hCVE-2026-839419.9 CRI—
———Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.5hCVE-2026-818235.3 MED—
———The vulnerability, if exploited, could allow an unauthenticated miscreant to perform read operations intended only for PIMBoards users, resulting in information disclosure. Write operations are not impacted.5hCVE-2026-730147.8 HIG—
———Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally.5hCVE-2026-729665.5 MED—
———Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally.5hCVE-2026-697248.8 HIG—
———Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.5h