Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes

The Hacker News - Oct 5, 2026

Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system. "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a

Read full article

More News