AI Weekly Malaysia

Back to items Summaries

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes

ID
31986
Status
summarized
Published
06 Oct 2026, 12:21 AM
Fetched
06 Oct 2026, 2:50 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/10/microsoft-exchange-flaw-lets.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.0
Created
06 Oct 2026, 2:51 AM
Tags
Audience
developerssaas_startup_founders

What happened

Microsoft released out-of-band updates for CVE-2026-96940, a CVSS 8.8 weak-authorization flaw in Exchange Server that lets an authenticated attacker escalate privileges and read other users' mailboxes and attachments within the same organization, though not cross-tenant. Affected on-prem builds include Exchange Server Subscription Edition RTM, 2016 Cumulative Update 23, and 2019 Cumulative Update 14 and 15; Exchange Online has a service-side fix and customers need no action. Microsoft tagged exploitability as 'Exploitation More Likely' and credited Jan Mitchell with reporting, but says there is no evidence of in-the-wild exploitation.

Why it matters

If your organization runs any listed on-prem Exchange build, apply the out-of-band update now because Microsoft rates exploitation as 'Exploitation More Likely' and an authenticated user in the same org could read other mailboxes. If you are only on Exchange Online, Microsoft says the service-side fix is already deployed and no action is required, so app developers using Microsoft 365 mail APIs do not need to change code.

Discussion angle

Ask who in the group still runs on-prem Exchange or has clients on the listed builds, and whether a same-org mailbox read plus 'Exploitation More Likely' changes their patch priority versus relying on Exchange Online's automatic fix.

Top