CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely
Microsoft has released out-of-band security updates for Exchange Server to fix CVE-2026-96940, a high-severity (CVSS 8.8) weak authorization flaw that can let an authenticated attacker gain higher privileges. Microsoft assesses exploitation as more likely, SecurityAffairs reports.