CVE-2026-96207 is a CVSS 10.0 improper certificate validation flaw in Microsoft Partner Center. An unauthenticated attacker could use it to elevate privileges over a network.
What Is It
CVE-2026-96207 is an improper certificate validation weakness (CWE-295) in Microsoft Partner Center. According to the NVD description, an unauthorized attacker can exploit it to elevate privileges over a network. Microsoft ([email protected]) assigned the CVE, and NVD published it on October 8, 2026. The record's status is "Received," which means NVD has not finished its analysis yet.
Why It Matters
Microsoft rates the flaw at the top of the scale: CVSS 3.1 base score 10.0 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N. In practice, that vector means:
- Network-reachable, with low attack complexity
- No privileges and no user interaction needed
- Changed scope, so the impact can reach beyond the vulnerable component
- High impact to confidentiality and integrity, with no impact to availability
The exploitability subscore is 3.9 and the impact subscore is 5.8.
Exploitation status: CISA's Known Exploited Vulnerabilities (KEV) catalog has no entry for this CVE. The supplied sources do not confirm active exploitation.
What's Vulnerable
- Vendor: Microsoft
- Product: Microsoft Partner Center
- Versions: Listed as affected with no specific version ("-")
Microsoft tagged the CVE as "exclusively-hosted-service." That tag means Microsoft runs the product as a hosted service, not as software that customers install. The record lists no affected CPEs.
Patch Status
The supplied NVD data has no specific remediation steps or fixed versions. Because the CVE is tagged as an exclusively hosted service, any fix would normally be applied on Microsoft's side. However, the provided record does not say whether a fix has been deployed or whether customers need to do anything. CISA has not issued a KEV required action or due date. Partner Center users should check the Microsoft Security Response Center (MSRC) advisory for official remediation guidance and any customer action items.
Sources
- NVD: CVE-2026-96207
- Microsoft Security Response Center: CVE-2026-96207
- CISA Known Exploited Vulnerabilities Catalog (no entry for this CVE at time of writing)