Improper Certificate Validation in Microsoft Partner Center by Microsoft
CVE-2026-96207

10CRITICAL

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
8 October 2026

What is CVE-2026-96207?

An improper certificate validation vulnerability exists in Microsoft Partner Center, allowing an unauthorized attacker to gain elevated privileges over a network. Exploiting this flaw could enable attackers to impersonate legitimate users or services, potentially leading to unauthorized access and manipulation of sensitive data. Organizations are encouraged to apply the latest security patches to mitigate this risk.

Affected Version(s)

Microsoft Partner Center -

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.