Mmastodon TechnologyCybersecurity first seen 3 h ago, last 3 h ago, peak #7
Microsoft Exchange flaw lets attackers read other users' mailboxes
Original: CVE-2026-96940 is an Exchange Server privilege escalation flaw rated CVSS 8.8. An authenticated attacker can potentially
A newly disclosed vulnerability in Microsoft Exchange Server, tracked as CVE-2026-96940, carries a high severity score of 8.8. Security researchers say an authenticated attacker could bypass authorization checks and read other users' mailboxes and attachments within the same on-premises Exchange organisation. The flaw does not allow pre-authentication remote code execution, but experts are warning administrators to review exposure and patch promptly.
Why now: A newly published high-severity Exchange vulnerability is being flagged to IT admins, prompting concern about mailbox data exposure.
MicrosoftExchange ServerCVE-2026-96940
Evidence
- CVE-2026-96940 is an Exchange Server privilege escalation flaw rated CVSS 8.8. An authenticated attacker can potentially bypass authorization checks and read other users' mailboxes and attachments within the same on-prem Exchange organization. No pre-auth RCE, but the mailbox… · thecybersecguru@infosec.exchange · 2
API: https://socialmediatrends-api.osmike.com/v1/trends/1200736