Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users’ Mailboxes

The Hacker News by The Hacker News
October 5, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananOct 05, 2026Vulnerability / Email Security

Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions.

The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system.

“Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network,” Microsoft said in an advisory released on October 2, 2026.

The Windows maker said an authenticated attacker can exploit this flaw to gain unauthorized access to other users’ mailboxes within the same organization and read email messages and attachments. However, the vulnerability does not allow cross-tenant access.

Microsoft has already deployed a “related service-side fix” to Exchange Online to address the issue. As a result, Exchange Online customers are not required to take any action.

Users of affected on-premises Microsoft Exchange Server products are advised to install the updates to stay protected. The following versions are impacted –

  • Microsoft Exchange Server Subscription Edition RTM
  • Microsoft Exchange Server 2016 Cumulative Update 23
  • Microsoft Exchange Server 2019 Cumulative Update 15
  • Microsoft Exchange Server 2019 Cumulative Update 14

Redmond has credited Microsoft researcher Jan Mitchell with discovering and reporting the flaw. Although there is no evidence of the flaw being weaponized in the wild, Microsoft has tagged it with an Exploitability assessment of “Exploitation More Likely,” making it essential that users move quickly to apply the fixes.

The disclosure comes days after Broadcom-owned Symantec warned that the China-linked Warlock actor is exploiting multiple vulnerabilities in Microsoft SharePoint to deploy its namesake ransomware in attacks targeting organizations in Portuguese- and Spanish-speaking countries.



Source link

The Hacker News

The Hacker News

Next Post

MediaTek y Airoha aceleran la modernización de la infraestructura de red global para la era de la IA

Recommended.

HPE Revs Up Its Networking Sales Charge, Names Aruba Veteran Phil Mottram To Lead Global Sales

HPE Revs Up Its Networking Sales Charge, Names Aruba Veteran Phil Mottram To Lead Global Sales

September 16, 2025
Critical RCE Flaws in Cisco ISE and ISE-PIC Allow Unauthenticated Attackers to Gain Root Access

Critical RCE Flaws in Cisco ISE and ISE-PIC Allow Unauthenticated Attackers to Gain Root Access

June 26, 2025

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
How ByteDance Made China’s Most Popular AI Chatbot

How ByteDance Made China’s Most Popular AI Chatbot

October 16, 2025
The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

June 9, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026

AWS Pours $6B Into New US Data Center As Amazon’s $220B Spending Goal Unfolds

August 20, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio