Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users’ Mailboxes

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users’ Mailboxes
Microsoft has issued out-of-band updates for CVE-2026-96940, a high-severity Microsoft Exchange Server flaw that could let an authenticated attacker escalate privileges and access other users’ mailboxes within the same organization. Exchange Online has already received a service-side fix, while on-premises users of affected Exchange Server versions should patch immediately; Microsoft also warned that exploitation is considered more likely. #MicrosoftExchangeServer #CVE-2026-96940

Keypoints

  • Microsoft patched CVE-2026-96940 with out-of-band security updates.
  • The flaw could let an authenticated attacker elevate privileges over the network.
  • Attackers may access other users’ mailboxes and read emails and attachments within the same organization.
  • Exchange Online was already protected by a related service-side fix.
  • Affected on-premises Exchange Server users should install the updates urgently.

Read More: https://thehackernews.com/2026/10/microsoft-exchange-flaw-lets.html