By The Hacker News
Publication Date: 2026-10-05 16:21:00
Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions.
The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system.
“Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network,” Microsoft said in an advisory released on October 2, 2026.
The Windows maker said an authenticated attacker can exploit this flaw to gain unauthorized access to other users’ mailboxes within the same organization and read email messages and attachments. However, the vulnerability does not allow cross-tenant access.
Microsoft has already deployed a “related service-side fix” to Exchange Online to address the issue. As a result, Exchange Online customers are not required to take any action.
Users of affected on-premises…



