Microsoft Exchange Server weak authorization privilege escalation (CVE-2026-96940)
Vulnerability
Summary
Hide ▲
Show ▼
A weak authorization flaw in Microsoft Exchange Server (CVE-2026-96940) lets an authenticated attacker elevate privileges and read other users' mailboxes within the same organization. Microsoft rated the issue 8.8 CVSS and released out-of-band security updates. The flaw affects on-premises Exchange Server deployments, while Exchange Online already has a service-side fix.
Related Happenings
NightEagle Russian enterprise VPN GhostContainer campaign
Campaign
H score37
First: 16.09.2026 18:27
Last: 16.09.2026 18:27
Sources 1
About this happening:
The NightEagle (APT-Q-95) campaign is actively using compromised VPN credentials and GhostContainer to reach Russian enterprise networks, increasing the risk of pe...
NightEagle Russian enterprise VPN GhostContainer campaign
CampaignAbout this happening: The NightEagle (APT-Q-95) campaign is actively using compromised VPN credentials and GhostContainer to reach Russian enterprise networks, increasing the risk of pe...
Microsoft Exchange Online service disruption causing authentication and email failures
Service Disruption
H score0
First: 31.08.2026 19:56
Last: 31.08.2026 19:56
Sources 1
About this happening:
Microsoft is investigating a widespread Exchange Online outage that is disrupting authentication and email delivery for tens of thousands of users. The issue i...
Microsoft Exchange Online service disruption causing authentication and email failures
Service DisruptionAbout this happening: Microsoft is investigating a widespread Exchange Online outage that is disrupting authentication and email delivery for tens of thousands of users. The issue i...
Latest development: 31.08.2026 20:30
Microsoft began investigating a widespread Exchange Online service issue after a stream of user reports on social media and a Downdetector spike indicated tens of thousands of affected users. The disruption is causing authentication-related errors, delays or failures when sending and receiving email, mailbox-operation problems, and access issues in Exchange administration experiences.
Microsoft Windows passkey relay mitigation for CVE-2026-34348
Advisory/Mitigation
H score31
First: 10.08.2026 15:25
Last: 10.08.2026 15:25
Sources 1
About this happening:
Microsoft's CVE-2026-34348 mitigation for Windows Event Logging Service and the reported passkey relay assertions issue reduces exposure to replay-style authentication...
Microsoft Windows passkey relay mitigation for CVE-2026-34348
Advisory/MitigationAbout this happening: Microsoft's CVE-2026-34348 mitigation for Windows Event Logging Service and the reported passkey relay assertions issue reduces exposure to replay-style authentication...
TA488 half-click Outlook Web Access espionage campaign
Campaign
H score42
First: 29.07.2026 18:10
Last: 29.07.2026 18:10
Sources 1
About this happening:
TA488 / Laundry Bear / Void Blizzard ran a half-click OWA campaign that abused CVE-2026-42897 in on-premises Microsoft Outlook Web Access on Exchange Ser...
TA488 half-click Outlook Web Access espionage campaign
CampaignAbout this happening: TA488 / Laundry Bear / Void Blizzard ran a half-click OWA campaign that abused CVE-2026-42897 in on-premises Microsoft Outlook Web Access on Exchange Ser...
CCB urgent patch warning for CVE-2026-41089 on Windows servers
Public Sector Action
H score48
First: 01.06.2026 15:30
Last: 01.06.2026 15:30
Sources 1
About this happening:
Belgium's CCB warned that CVE-2026-41089 is being actively exploited in the wild, urging admins to immediately patch vulnerable Windows servers because the fla...
CCB urgent patch warning for CVE-2026-41089 on Windows servers
Public Sector ActionAbout this happening: Belgium's CCB warned that CVE-2026-41089 is being actively exploited in the wild, urging admins to immediately patch vulnerable Windows servers because the fla...
Timeline
-
05.10.2026 19:21 2 articles · 3h ago
Microsoft details mailbox exposure and patch status for CVE-2026-96940
Technical Analysis UpdateCVE-2026-96940 is rated 8.8 CVSS and can let an authenticated attacker read email messages and attachments in other users' mailboxes within the same organization; the flaw does not permit cross-tenant access, Exchange Online already has a related service-side fix, and affected on-premises products include Microsoft Exchange Server Subscription Edition RTM, Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 15, and Microsoft Exchange Server 2019 Cumulative Update 14. Microsoft also tags the issue with an Exploitability assessment of "Exploitation More Likely" and says there is no evidence of weaponization in the wild.
Show sources
- Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes — thehackernews.com — 05.10.2026 19:21
- Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes — thehackernews.com — 05.10.2026 19:21
-
02.10.2026 03:00 1 articles · 3d ago
Microsoft releases Exchange Server out-of-band updates for CVE-2026-96940
Initial DisclosureMicrosoft releases out-of-band security updates for Microsoft Exchange Server after identifying CVE-2026-96940, a weak-authorization flaw that lets an authenticated attacker elevate privileges over a network and gain unauthorized access to other users' mailboxes within the same organization.
Show sources
- Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes — thehackernews.com — 05.10.2026 19:21