importantSYS.SOURCE: The Hacker News• 2026-10-05T21:51:52+05:30
Microsoft Exchange Vulnerability Allows Privilege Escalation and Unauthorized Mailbox Access
Microsoft Exchange Server has a high-severity vulnerability (CVE-2026-96940) allowing authenticated attackers to access other users' mailboxes. Microsoft released updates to address the flaw, affecting specific on-premises versions while Exchange Online is already protected.
Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions.
The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system.
"Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a
*** END OF TRANSMISSION ***