Microsoft Exchange flaw lets attackers access mailboxes
Microsoft has released urgent updates for Exchange Server after disclosing a high-severity vulnerability, CVE-2026-96940. The flaw allows attackers with any valid account on Exchange to access other users’ mailboxes, potentially exposing emails and attachments organization-wide. Microsoft rates the risk of exploitation as high, although there is no evidence of attacks in the wild. Exchange Online is already protected, but on-premises servers require manual patching to prevent abuse.
- Vulnerability allows privilege escalation within Exchange Server
- Attackers need an authenticated Exchange account
- No cross-tenant access is possible
- Exchange Online protected already; on-premises servers must patch
- No active exploitation reported, but exploitation labeled likely
Sources covering this
In this story
More in Cybersecurity
Hackers send extortion message through ASOS app
Hackers took control of ASOS's app notification system and sent a message to users claiming to have breached the company's Snowflake…
ClickFix attacks use browser cache to smuggle payloads
A recent ClickFix campaign is hiding malicious Visual Basic scripts disguised as image files in browser caches on victims' devices,…
Phishing campaign uses fake AI ad tools to steal credentials
Researchers report a phishing operation targeting digital advertising professionals through counterfeit AI tools like ChatGPT, Gemini,…
Nikkei reveals breaches of employee email accounts
Japanese media group Nikkei disclosed that two employee cloud email accounts were breached in separate incidents this year.