An updated version of the September 2026 Scan Cab is available

🚨 The Signal: An updated Exchange Server Scan Cab is available, addressing CVE-2026-96940, an Elevation of Privilege vulnerability. Re-deploying the updated Scan Cab is critical for environments using it to assess Exchange Server update compliance, ensuring timely application of security patches.

The Impact

IT administrators using Scan Cab for Exchange Server must update it to mitigate an Elevation of Privilege vulnerability.

  • IT administrators: Must re-deploy Scan Cab to ensure accurate vulnerability assessment.
  • Security teams: Risk of unpatched Exchange Server vulnerabilities if Scan Cab is not updated.
  • Organisations: Potential for Elevation of Privilege if Exchange Server remains unpatched.

The Action

  1. Identify if your environment uses Scan Cab for Exchange Server update compliance.
  2. If applicable, re-acquire the updated September 2026 Scan Cab from Microsoft.
  3. Re-deploy the updated Scan Cab using your organisation's standard update processes.
  4. Verify that the updated Scan Cab is correctly assessing Exchange Server updates.

Domain: Exchange · Impact: high · Workload: Exchange Online · Essential Eight: Patch Applications, Patch Operating Systems · ISM: ISM-0304, ISM-1407, ISM-1501, ISM-1621, ISM-1622, ISM-1623, ISM-1654, ISM-1655, ISM-1690, ISM-1691, ISM-1692, ISM-1693, ISM-1694, ISM-1695, ISM-1696, ISM-1698, ISM-1699, ISM-1700, ISM-1701, ISM-1702, ISM-1704, ISM-1807, ISM-1808, ISM-1876, ISM-1877, ISM-1889, ISM-1901, ISM-1902, ISM-1905