Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely

What happened
Microsoft released emergency updates for Exchange Server to fix CVE-2026-96940 (the public catalogue number for a specific software flaw), a high-severity flaw that can let attackers gain higher privileges. Microsoft has released out-of-band security updates for Exchange Server to fix a high-severity vulnerability tracked as CVE-2026-96940 (CVSS score of 8.8). Microsoft is a software and software development company based in Redmond.
Microsoft disclosed the issue on October 2, 2026, and urged customers to install the security updates. “An authenticated attacker who successfully exploited this vulnerability could gain unauthorized access to other users’ mailboxes within the same organization and read email messages and attachments.”
The flaw is caused by weak authorization and can allow an authenticated attacker to gain higher privileges over a network. “The vulnerability does not allow access across tenant boundaries.”
Key facts
- Microsoft — released: emergency updates for Exchange Server to fix CVE-2026-96940, a high-severity flaw that can let attackers gain higher privileges
- Microsoft has — released: out-of-band security updates for Exchange Server to fix a high-severity vulnerability tracked as CVE-2026-96940 (CVSS score of 8.8)
Sources & evidence
- Security Affairs Reporting source
CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely ↗
https://securityaffairs.com/200476/security/cve-2026-96940-microsoft-fixes-high-severity-exchange-server-flaw.html