Microsoft issues emergency Exchange Server fixes for privilege escalation flaw
The vulnerability, tracked as CVE-2026-96940, involves weak authorization that can allow authenticated attackers to gain higher privileges under certain conditions. TechRadar reports that Exchange Server 2016 and 2019 are affected and that the flaw can expose mailboxes across an organization, allowing attackers to read other users' messages.
- The vulnerability has a CVSS severity score of 8.8.
Covered by 3 publishers within 22 hours of the first report.
Reporting3
The Hacker News Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes · info@thehackernews.com (The Hacker News)
Security Affairs CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely · Pierluigi Paganini
TechRadar Microsoft Exchange flaw allows hackers to read mailboxes across an organization, so patch now · Sead Fadilpašić
Related
Topics Microsoft