Home › Microsoft Patch Tuesday › October 2026

Microsoft Patch Tuesday, October 2026

·

Microsoft's October 2026 security release, published October 13, 2026: 4 updates fixing 1 CVE, ranked by confirmed exploitation, ransomware use, and severity. Provided by Senserva.

4
Updates (KBs)
1
CVEs fixed
0
On the CISA KEV list
0
Critical updates

Actively exploited CVEs (CISA KEV)

None of this month's CVEs were in the CISA Known Exploited Vulnerabilities catalog as of the last refresh.

Other high-risk CVEs (CVSS 8.8+)

CVE-2026-96940Microsoft Exchange Server Elevation of Privilege VulnerabilityCVSS 8.8

Products fixed this month

Microsoft Exchange Server 2019 Cumulative Update 14 (1)Microsoft Exchange Server 2016 Cumulative Update 23 (1)Microsoft Exchange Server Subscription Edition RTM (1)Microsoft Exchange Server 2019 Cumulative Update 15 (1)

Every update in this release

All 4 update articles, worst first: anything on the CISA KEV list, then by highest CVSS. Each row links our page for the update, Microsoft's support article, and the Update Catalog for a standalone download.

UpdateSeverityMax CVSSCVEs fixedProductsAlso
KB5129957High8.81Microsoft Exchange Server 2019 Cumulative Update 14Support · Catalog
KB5129958High8.81Microsoft Exchange Server 2016 Cumulative Update 23Support · Catalog
KB5129955High8.81Microsoft Exchange Server Subscription Edition RTMSupport · Catalog
KB5129956High8.81Microsoft Exchange Server 2019 Cumulative Update 15Support · Catalog
Take this release to your AI

Composed from the October 2026 release data above. Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Now see your own patch state.

Senserva reads your Microsoft 365, Intune, Defender, and Entra ID environment and turns this release into your list: every update still missing, on every device, ranked by what attackers are actually exploiting. The 650+ configuration checks come with it.

1Find it2Fix it3Prove it
Start my free patch auditAll you do is register.
Reference: Microsoft CVE and vulnerability management, ranked by real-world risk, and the Microsoft patching guide.
Data notice: this page is provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative Microsoft advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva EULA.