hacker-news · Crawled Oct 5, 2026
Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
Read original article ↗AI Summary
Microsoft disclosed a high-severity vulnerability, CVE-2026-96940, in on-premises Microsoft Exchange Server that allows authenticated attackers to escalate privileges and access other users' mailboxes within the same organization. The flaw stems from weak authorization controls and has been rated 8.8 on the CVSS scale. Although no active exploitation has been observed, Microsoft considers exploitation likely and has issued out-of-band updates for affected versions. Exchange Online has been mitigated via a server-side fix and does not require customer action.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.