Site icon VMVirtualMachine.com

CVE-2026-96940: Critical Microsoft Exchange Server Vulnerability Enables Privilege Escalation and Unauthorized Mailbox Access

CVE-2026-96940: Critical Microsoft Exchange Server Vulnerability Enables Privilege Escalation and Unauthorized Mailbox Access

By Rescana
Publication Date: 2026-10-06 00:00:00

Executive Summary

A critical vulnerability, CVE-2026-96940, has been identified in Microsoft Exchange Server, enabling authenticated attackers to escalate privileges and read the mailboxes of other users within the same organization. This flaw, rated CVSS 8.8 and assessed as “Exploitation More Likely” by Microsoft, affects on-premises Exchange deployments and has prompted an out-of-band security update. While there is currently no evidence of exploitation in the wild and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, the risk profile and attack surface make rapid remediation essential. Organizations running affected versions of Microsoft Exchange Server should prioritize patching and review access logs for anomalous activity.

Technical Information

CVE-2026-96940 is a privilege escalation vulnerability rooted in the authorization logic of Microsoft Exchange Server. Under specific conditions, an authenticated user can exploit this flaw to…

Exit mobile version