Detalle de la noticia

Vulnerabilidad

Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940)

Fuente: Help Net Security Publicado: 05/10/2026 · 10:38 UTC

También cubierto por: The Hacker News

Compartir:
Vulnerabilidad Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940)
Imagen: Help Net Security

Mi­cro­soft has pushed out an out-of-band se­cu­rity up­da­te for Ex­chan­ge Ser­ver that fixes a high-se­ve­rity vul­ne­ra­bi­lity (CVE-2026-96940) that may allow authen­ti­ca­ted at­tac­kers to read emails and at­tach­ments of other users in the same or­ga­ni­za­tion, but “does not allow ac­cess across te­nant boun­da­ries.” CVE-2026-96940 was dis­co­ve­red in­ter­nally and, ac­cor­ding to the Ex­chan­ge Ser­ver Team, they “are not aware of ac­ti­ve ex­ploi­ta­tion.” Ne­verthe­less, Mi­cro­soft thinks that the flaw could be con­sis­tently ex­ploi­ted and notes that this type … More → The post Out-of-band Ex­chan­ge Ser­ver up­da­te fixes high-se­ve­rity mail­box ac­cess bug (CVE-2026-96940) ap­pea­red first on Help Net Se­cu­rity .