Home / Oct 06, 2026 / Story
0
#4 The Hacker News general October 05, 2026 at 16:21 UTC

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes

By [email protected] (The Hacker News)

AI Summary

Microsoft issued an out-of-band patch for CVE-2026-96940 (CVSS 8.8), a high-severity weak authorization flaw in Microsoft Exchange Server that allows authenticated attackers to read other users' mailboxes by escalating privileges. The out-of-band release indicates Microsoft assessed the risk as urgent enough not to wait for the next Patch Tuesday cycle. Exchange administrators should prioritize applying this update, particularly in environments where insider threat or compromised account scenarios are a concern.

Relevance score: 83.0/100

# More from October 06