Search
Find merged stories by title or summary.
Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system. "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a
Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940)
Microsoft has pushed out an out-of-band security update for Exchange Server that fixes a high-severity vulnerability (CVE-2026-96940) that may allow authenticated attackers to read emails and attachments of other users in the same organization, but “does not allow access across tenant boundaries.” CVE-2026-96940 was discovered internally and, according to the Exchange Server Team, they “are not aware of active exploitation.” Nevertheless, Microsoft thinks that the flaw could be consistently exploited and notes that this type … More → The post Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940) appeared first on Help Net Security .
CVE-2026-96940 Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE ID : CVE-2026-96940 Published : Oct. 2, 2026, 7:06 p. m. • 22 minutes ago Description : None Severity: 8.8 • HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
You've reached the end of current stories for this search.
