hacker-news · Crawled Oct 5, 2026

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes

Read original article ↗

AI Summary

Microsoft disclosed a high-severity vulnerability, CVE-2026-96940, in on-premises Microsoft Exchange Server that allows authenticated attackers to escalate privileges and access other users' mailboxes within the same organization. The flaw stems from weak authorization controls and has been rated 8.8 on the CVSS scale. Although no active exploitation has been observed, Microsoft considers exploitation likely and has issued out-of-band updates for affected versions. Exchange Online has been mitigated via a server-side fix and does not require customer action.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.