Microsoft Patches High Severity Privilege Escalation Flaw in Exchange Server
Microsoft has issued out-of-band updates to patch a high-severity security vulnerability in Exchange Server that allowed authenticated users to access other mailboxes.
FTMQ Security, written by our newsroom0 views

Microsoft released emergency out-of-band security updates to address a high-severity privilege escalation flaw in Microsoft Exchange Server, The Hacker News reported. The vulnerability allows an authenticated attacker to read electronic mailboxes belonging to other users within the same organisation over a network. [1]
The security flaw is tracked as CVE-2026-96940 and carries a CVSS severity rating of 8.8. According to The Hacker News, Microsoft released an official advisory on October 2, 2026, stating that weak authorization mechanisms in Exchange Server caused the problem. [1][4]
RS Web Solutions and Cybersecurity News both report that Microsoft launched an updated Exchange V2 release following the discovery of the security vulnerability. Electronic mailboxes serve as the primary destination where electronic mail messages are delivered across network applications, Wikipedia notes. [2][3][6]
In short
- Microsoft released emergency out-of-band updates for a high-severity Exchange Server flaw.
- The flaw is tracked as CVE-2026-96940 and has a CVSS score of 8.8.
- Weak authorization allows authenticated attackers to read mailboxes of other users in the same organisation.
Sources
Every paragraph above points to the numbered items it rests on. Read the originals here.
- [1]Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' MailboxesThe Hacker News, 22h ago (the report this story comes from)
- [2]Microsoft Launches Exchange V2 Update After Security Flaw FoundRS Web Solutions, 1d ago
- [3]Microsoft Pushes New Exchange V2 Update After Discovering New Security Flawcybersecuritynews.com, 1d ago
- [4]Exchange Flaw CVE-2026-96940 Exposes Users’ Mailboxescyberkendra.com, 20h ago
Background
- [5]Transport Layer Security on Wikipedia
- [6]Email box on Wikipedia
Our newsroom writes these reports with the help of software, from the 6 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.
Related from FTMQ Security
Earlier reports of ours on the same people and subjects.
- Citrix issues patches for NetScaler memory overflow flaw under active attackBugs and Patches, 14h ago
- Citrix issues emergency updates for NetScaler zero day vulnerabilityTop Stories, 1d ago
- Hackers target Rejetto HFS servers following critical session forgery vulnerability discoveryTop Stories, 16h ago
More in Top Stories
- ShinyHunters exploits PeopleSoft zero day hole as FBI arrests suspected member13h ago
- OpenAI introduces invisible text watermarking for ChatGPT and Codex in EU14h ago
- Hackers target Rejetto HFS servers following critical session forgery vulnerability discovery16h ago
- ClingSTUN Malware Compromises Unpatched IoT Devices as Proxy Nodes16h ago
- China Aligned TA419 Targets US AI Experts With Phishing Attacks1d ago
- Citrix issues emergency updates for NetScaler zero day vulnerability1d ago
Get the day in one email
Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments
Loading
Join the conversation
Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.
Already on the list? Enter the same address and we will send a sign-in link.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.