Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes

Executive Summary

Microsoft released out‑of‑band patches for a high‑severity flaw (CVE‑2026‑96940) in Exchange Server that allows authenticated attackers to elevate privileges and read other users’ mailboxes. The vulnerability scores 8.8 on CVSS and could be exploited under certain conditions.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-10-05T16:21:52+00:00 - Category: vulnerabilities

Original Description: Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system. "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a

"The best cure for the body is a quiet mind."

— Napoleon Bonaparte
Source: The Hacker News