CVE-2026-96940
Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
- CVSS
- 8.8
- EPSS
- 0.005 (40.4th percentile)
- CISA KEV
- Not listed
- Exploitation
- none
- Public exploits
- None seen
- State
- PUBLISHED
Coverage
Help Net SecuritySpecialist. Specialist publisher: established trade press, or expert analysis with a track record
Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940)
Microsoft has pushed out an out-of-band security update for Exchange Server that fixes a high-severity vulnerability (CVE-2026-96940) that may allow authenticated attackers to read emails and attachments of other users in the same organization, but “does not allow access across tenant boundaries.”…
Microsoft MSRCAuthoritative. Authoritative publisher: a primary source, or a newsroom with formal editorial standards
CVE-2026-96940 Microsoft Exchange Server Elevation of Privilege Vulnerability
Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
What we observed
No signals recorded