Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
Microsoft has released out-of-band security updates for a high-severity flaw in Microsoft Exchange Server tracked as CVE-2026-96940 (CVSS 8.8). Weak authorization allows an authenticated attacker to elevate privileges and read other users' mailboxes under certain conditions.