Microsoft has issued out-of-band updates for CVE-2026-96940, a high-severity Microsoft Exchange Server flaw that could let an authenticated attacker escalate privileges and access other users’ mailboxes within the same organization. Exchange Online has already received a service-side fix, while on-premises users of affected Exchange Server versions should patch immediately; Microsoft also warned that exploitation is considered more likely. #MicrosoftExchangeServer #CVE-2026-96940
Keypoints
- Microsoft patched CVE-2026-96940 with out-of-band security updates.
- The flaw could let an authenticated attacker elevate privileges over the network.
- Attackers may access other users’ mailboxes and read emails and attachments within the same organization.
- Exchange Online was already protected by a related service-side fix.
- Affected on-premises Exchange Server users should install the updates urgently.
Read More: https://thehackernews.com/2026/10/microsoft-exchange-flaw-lets.html