醫療 IT 維運報告|2026-10-06
- 彙整區間: 2026-09-29~2026-10-06(台北時間)
- 查核時間: 2026-10-06 07:00(台北時間)
- 去重基準: 比對最近一期
2026-10-05.md及近期本系列 cron 輸出;僅列本期新增公告或已到實施節點的實質更新,不重述沒有新變化的舊項目。 - 本期項目: 官方確認 3 項;未證實警訊 0 項。
本期重點
- Exchange Server V2 安全更新加入 CVE-2026-96940;MSRC 評估「較可能遭利用」,但 Exchange 團隊表示尚未發現實際利用情形。[1][2]
- 持續追蹤: Microsoft Entra Connect Sync 最低版本期限已於 9/30 經過;低於 2.5.79.0 的同步服務可能在服務變更生效時失敗。[5]
- Windows 記憶體完整性保護自 10 月起逐步推送至符合資格的裝置;既有系統管理員/使用者設定仍受尊重。[6]
1. Exchange Server:V2 安全更新新增 CVE-2026-96940
- 發布日期: Microsoft Exchange Team 於 2026-10-02 發布 2026 年 9 月 V2 Exchange Server 安全更新,與原版的差異是新增 CVE-2026-96940。[2]
- 受影響產品與版本: Exchange Server Subscription Edition RTM、Exchange Server 2019 CU14/CU15,以及 Exchange Server 2016 CU23;2019/2016 版本須加入 Period 2 ESU 才可取得相應更新。[2] MSRC 部署清單列出的對應 KB 為 KB5129955、KB5129956、KB5129957、KB5129958。[3] Microsoft 支援頁確認 KB5129955 是 2026-10-02 發布的 Exchange Server Subscription Edition RTM V2 安全更新。[4]
- 官方狀態/變更: MSRC 將此弱點分類為 Exchange Server 權限提升,CVSS 基礎分數 8.8,並評估「較可能遭利用」;Exchange 團隊表示尚未發現實際利用情形。[1][2]
- 對醫療 IT 的具體影響: 若院方仍有受影響的地端 Exchange,經驗證的攻擊者可能取得同一組織內其他使用者信箱及郵件附件的未授權存取;Microsoft 表示此弱點不允許跨租戶存取。[1] Exchange Online 已有服務端修正,但混合式環境仍須更新地端 Exchange 伺服器及執行 Exchange Management Tools 的設備。[2]
- 建議處置: 盤點地端 Exchange 伺服器及管理工具設備,以 Exchange Server Health Checker 確認版本與待辦更新,並依適用版本安裝 V2 安全更新;Microsoft 建議儘早套用,且建議涵蓋所有 Exchange Server 與管理工具設備。[2]
- 明確期限: Microsoft 未公告統一日曆截止日;官方建議為「儘早」套用,不另行推定院內期限。[2]
2. Microsoft Entra Connect Sync:期限已過,持續追蹤同步版本
- 事件/期限: Microsoft 要求客戶於 2026-09-30 前升級,以避免服務中斷;本期查核時該日期已過。[5]
- 受影響產品與版本: Microsoft Entra Connect Sync;最低需求版本為 2.5.79.0 或更新版本。[5]
- 官方狀態/變更: 若未升級至最低版本,Microsoft 表示服務變更生效時,Entra Connect Sync 的所有同步服務都可能失敗;若期限後才升級,官方指出同步功能中斷期間會持續到完成升級。[5] 官方文件未表示這項服務變更已對所有租戶全面生效,因此不推定院內或其他租戶已發生中斷。[5]
- 對醫療 IT 的具體影響: 若院內仍使用低於最低版本的 Connect Sync,可能影響內部 Active Directory 與 Entra ID 之間的帳號/目錄同步;醫療人員帳號異動及依雲端目錄控管的服務權限應列入核對。[5]
- 建議處置: 立即查核 Connect Sync 實際版本;低於 2.5.79.0 時,依 Microsoft 指引升級至 2.5.79.0 或更新版本,並確認同步工作恢復正常。[5]
- 明確期限: 官方原期限為 2026-09-30,現已經過;文件未提供新的寬限日期。若尚未升級,應視為逾期處理,不應等待新期限。[5]
3. Windows:記憶體完整性保護開始逐步啟用
- 公告/實施時間: Microsoft Windows IT Pro Blog 於 2026-09-01 公告,Windows 品質更新自 2026 年 10 月起,將逐步在符合資格的裝置啟用記憶體完整性保護。[6]
- 受影響產品與版本: 公告範圍為符合資格的 Windows 裝置;該公告未列出特定 Windows 版本或每台裝置的固定推送日期。[6]
- 官方狀態/變更: 品質更新會在合格裝置啟用記憶體完整性;若尚未啟用,部分裝置也會啟用 Virtualization-based Security(VBS)。Microsoft 表示會漸進推出,並依硬體能力、相容性及效能條件評估準備度;既有系統管理員與使用者設定/原則仍會沿用,已明確停用的裝置不會被此推送自動改回啟用。[6]
- 對醫療 IT 的具體影響: 若院內臨床工作站或醫療設備控制端符合推送條件,新增核心防護設定可能涉及既有驅動程式、周邊及臨床應用程式相容性;這是維運測試建議,並非 Microsoft 已通報的院內故障。[6]
- 建議處置: 在既有 Windows 更新環境分批驗證記憶體完整性/VBS 狀態,優先涵蓋臨床應用、醫療設備介接與必要周邊;確認目前套用的管理原則符合院內安全基準,再依既有變更流程擴大部署。[6]
- 明確期限: 官方僅說明自 2026 年 10 月開始漸進推出,未提供所有裝置共通的完成期限;不自行設定院內截止日。[6]
去重與查核界線
- 本期僅納入上述 3 項官方公告/狀態更新;未證實社群警訊 0 項。
- 醫療 IT 影響均以「院內確有相應產品或設定」為前提;本報告未取得院內資產清冊或租戶狀態,不能據此判定院內是否實際受影響。
Sources
[1] CVE-2026-96940 - Microsoft Security Update Guidehttps://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-96940
Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
Exploitation More Likely
read email messages and attachments. The vulnerability does not allow access across tenant boundaries.
Elevation of Privilege
CVSS:3.1 8.8 / 7.7
[2] Released: September 2026 V2 Exchange Server Security Updateshttps://techcommunity.microsoft.com/blog/exchange/released-september-2026-v2-exchange-server-security-updates/4561718
The difference between the original September 2026 Security Update release and this V2 release is an addition of CVE-2026-96940.
We recommend that customers review the deployment guidance and apply the update at the earliest opportunity.
We identified the vulnerability internally and are not aware of active exploitation.
These vulnerabilities affect Exchange Server. Exchange Online customers are already protected from the vulnerabilities addressed by these SUs and do not need to take any action other than updating any Exchange servers or Exchange Management tools workstations in their environment.
Exchange Server 2019 CU14 and CU15 (to access, organization must be enrolled into the Period 2 ESU program)
Exchange Server Subscription Edition RTM
Exchange Server 2016 CU23 (to access, organization must be enrolled into the Period 2 ESU program)
[3] MSRC Security Update Guide: Deploymentshttps://msrc.microsoft.com/update-guide/deployments
Title: Knowledge Base Article for Microsoft Exchange Server Subscription Edition RTM, 1 link, Content:5129955
Title: Knowledge Base Article for Microsoft Exchange Server 2019 Cumulative Update 15, 1 link, Content:5129956
Title: Knowledge Base Article for Microsoft Exchange Server 2019 Cumulative Update 14, 1 link, Content:5129957
Title: Knowledge Base Article for Microsoft Exchange Server 2016 Cumulative Update 23, 1 link, Content:5129958
[4] Exchange Server Subscription Edition RTM October 2, 2026 SU (KB5129955)https://support.microsoft.com/help/5129955
Description of version 2 of the security update for Microsoft Exchange Server Subscription Edition RTM October 2, 2026 (KB5129955)
[5] Hardening updates for Microsoft Entra Connect Synchttps://learn.microsoft.com/en-us/entra/identity/hybrid/connect/harden-update-ad-fs-pingfederate
All customers are required to upgrade to the minimum versions by September 30, 2026 to avoid service disruptions.
All synchronization services in Microsoft Entra Connect Sync will fail.
Version 2.5.79.0 or higher.
[6] Expanding memory integrity protection across Windows deviceshttps://techcommunity.microsoft.com/blog/windows-itpro-blog/expanding-memory-integrity-protection-across-windows-devices/4551984
Beginning in October 2026, Microsoft will expand memory integrity protection across eligible devices, helping you and your organization benefit from stronger kernel-level protection from sophisticated attacks by default with little or no additional configuration.
Windows quality updates will begin enabling memory integrity protection on eligible devices.
Readiness signals include hardware capabilities, compatibility, and performance considerations.
Existing administrator and user decisions and policies remain in effect.
To help ensure a reliable device experience, Windows automatically evaluates readiness before enabling memory integrity.
If memory integrity is not enabled by default, users and organizations can still review, configure, and enable it using existing Windows security and management tools.
This means that devices where memory integrity has already been disabled won't be automatically changed by this rollout.