Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users’ Mailboxes
thehackernews.com Oct 6, 2026

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users’ Mailboxes

AI-summarised brief · reviewed before publication

Microsoft issued out‑of‑band patches for a high‑severity flaw (CVE‑2026‑96940) in Exchange Server that allows authenticated attackers to elevate privileges and read other users’ mailboxes within the same organization. The vulnerability, rated 8.8 on CVSS, does not enable cross‑tenant access. Microsoft has already fixed Exchange Online, so those users need not act, but on‑premises customers must install the updates. The flaw was discovered by researcher Jan Mitchell, and Microsoft flags it as “Exploitation More Likely.”

💡 Why It Matters

  • · The patch protects internal mail traffic from privilege‑escalation attacks that could expose sensitive corporate communications.