醫療 IT 維運報告|2026-10-06

本期重點

  1. Exchange Server V2 安全更新加入 CVE-2026-96940;MSRC 評估「較可能遭利用」,但 Exchange 團隊表示尚未發現實際利用情形。[1][2]
  2. 持續追蹤: Microsoft Entra Connect Sync 最低版本期限已於 9/30 經過;低於 2.5.79.0 的同步服務可能在服務變更生效時失敗。[5]
  3. Windows 記憶體完整性保護自 10 月起逐步推送至符合資格的裝置;既有系統管理員/使用者設定仍受尊重。[6]

1. Exchange Server:V2 安全更新新增 CVE-2026-96940

2. Microsoft Entra Connect Sync:期限已過,持續追蹤同步版本

3. Windows:記憶體完整性保護開始逐步啟用

去重與查核界線

Sources

[1] CVE-2026-96940 - Microsoft Security Update Guide
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-96940

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
Exploitation More Likely
read email messages and attachments. The vulnerability does not allow access across tenant boundaries.
Elevation of Privilege
CVSS:3.1 8.8 / 7.7

[2] Released: September 2026 V2 Exchange Server Security Updates
https://techcommunity.microsoft.com/blog/exchange/released-september-2026-v2-exchange-server-security-updates/4561718

The difference between the original September 2026 Security Update release and this V2 release is an addition of CVE-2026-96940.
We recommend that customers review the deployment guidance and apply the update at the earliest opportunity.
We identified the vulnerability internally and are not aware of active exploitation.
These vulnerabilities affect Exchange Server. Exchange Online customers are already protected from the vulnerabilities addressed by these SUs and do not need to take any action other than updating any Exchange servers or Exchange Management tools workstations in their environment.
Exchange Server 2019 CU14 and CU15 (to access, organization must be enrolled into the Period 2 ESU program)
Exchange Server Subscription Edition RTM
Exchange Server 2016 CU23 (to access, organization must be enrolled into the Period 2 ESU program)

[3] MSRC Security Update Guide: Deployments
https://msrc.microsoft.com/update-guide/deployments

Title: Knowledge Base Article for Microsoft Exchange Server Subscription Edition RTM, 1 link, Content:5129955
Title: Knowledge Base Article for Microsoft Exchange Server 2019 Cumulative Update 15, 1 link, Content:5129956
Title: Knowledge Base Article for Microsoft Exchange Server 2019 Cumulative Update 14, 1 link, Content:5129957
Title: Knowledge Base Article for Microsoft Exchange Server 2016 Cumulative Update 23, 1 link, Content:5129958

[4] Exchange Server Subscription Edition RTM October 2, 2026 SU (KB5129955)
https://support.microsoft.com/help/5129955

Description of version 2 of the security update for Microsoft Exchange Server Subscription Edition RTM October 2, 2026 (KB5129955)

[5] Hardening updates for Microsoft Entra Connect Sync
https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/harden-update-ad-fs-pingfederate

All customers are required to upgrade to the minimum versions by September 30, 2026 to avoid service disruptions.
All synchronization services in Microsoft Entra Connect Sync will fail.
Version 2.5.79.0 or higher.

[6] Expanding memory integrity protection across Windows devices
https://techcommunity.microsoft.com/blog/windows-itpro-blog/expanding-memory-integrity-protection-across-windows-devices/4551984

Beginning in October 2026, Microsoft will expand memory integrity protection across eligible devices, helping you and your organization benefit from stronger kernel-level protection from sophisticated attacks by default with little or no additional configuration.
Windows quality updates will begin enabling memory integrity protection on eligible devices.
Readiness signals include hardware capabilities, compatibility, and performance considerations.
Existing administrator and user decisions and policies remain in effect.
To help ensure a reliable device experience, Windows automatically evaluates readiness before enabling memory integrity.
If memory integrity is not enabled by default, users and organizations can still review, configure, and enable it using existing Windows security and management tools.
This means that devices where memory integrity has already been disabled won't be automatically changed by this rollout.