Microsoft issues emergency Exchange Server fixes for privilege escalation flaw

First reported by The Hacker News at · Updated · 3 sources

The vulnerability, tracked as CVE-2026-96940, involves weak authorization that can allow authenticated attackers to gain higher privileges under certain conditions. TechRadar reports that Exchange Server 2016 and 2019 are affected and that the flaw can expose mailboxes across an organization, allowing attackers to read other users' messages.

  • The vulnerability has a CVSS severity score of 8.8.

Covered by 3 publishers within 22 hours of the first report.

Reporting3

The Hacker News Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes · info@thehackernews.com (The Hacker News)

Related

Topics Microsoft