Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
Microsoft releases out-of-band security updates for a high-severity Microsoft Exchange Server flaw that lets authenticated attackers elevate privileges under certain conditions. Tracked as CVE-2026-96940 and rated 8.8 on CVSS, the vulnerability concerns weak authorization and can allow access to other users’ mailboxes.
Exchange administrators should apply the out-of-band updates to address a high-severity authorization flaw that can expose other users’ mailboxes and enable privilege escalation.