⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users’ Mailboxes

October 5, 2026

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes Ravie LakshmananOct 05, 2026Vulnerability / Email Security Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system. "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network," Microsoft said in an advisory released on October 2, 2026. The Windows maker said an authenticated attacker can exploit this flaw to gain unauthorized access to other users' mailboxes within the same organization and read email messages and attachments. However, the vulnerability does not allow cross-tenant access. Microsoft…

CVEs: CVE-2026-96940, CVE-2026-88772