Image: img.helpnetsecurity.com · rights & removal
Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE
Reporting by Help Net SecurityRead the original at helpnetsecurity.com
Executive Summary
Facts Only
* Microsoft pushed an out-of-band security update for Exchange Server.
* The update fixes vulnerability CVE-2026-96940.
* CVE-2026-96940 may allow authenticated attackers to read emails and attachments of other users in the same organization.
* The vulnerability does not allow access across tenant boundaries.
* The Exchange Server Team is not aware of active exploitation of CVE-2026-96940.
* Microsoft advises administrators to update sooner rather than later due to potential consistent exploitation.
* A related service-side fix was deployed to Exchange Online late last week.
* The rollout lacked an immediate KB article explaining the content.
* The security update is available for on-prem servers running specific Exchange Server versions and cumulative updates (RTM, 2019 CU14/15, 2016 CU23).
* Microsoft recommends installing Service Updates on all Exchange Servers and related management tools.
Full Take
From the original · Help Net Security
2026-96940) Microsoft has pushed out an out-of-band security update for Exchange Server that fixes a high-severity vulnerability (CVE-2026-96940) that may allow authenticated attackers to read emails and attachments of other users in the same organization, but “does not allow access across tenant boundaries.”Read the full story at helpnetsecurity.com
Sentinel — Human
The text reads like standard technical news reporting that has been lightly edited for flow, leaning toward human authorship rather than pure synthetic generation.
