Urgent.News

What's breaking now, across thousands of outlets.

Tech

Microsoft Exchange flaw allows hackers to read mailboxes across an organization, so patch now

Microsoft Exchange Server 2016 and 2019 affected, but Microsoft released a fix.

Microsoft Exchange flaw allows hackers to read mailboxes across an organization, so patch now

Microsoft has released a critical patch for a high-severity flaw in Exchange Server that could allow attackers to access other users' mailboxes within the same organization. The vulnerability, known as CVE-2026-96940, has been labeled as "exploitation more likely" by Microsoft, suggesting a high likelihood of abuse by cybercriminals.

To exploit the flaw, attackers would need to compromise a user's credentials, which is relatively easy given the prevalence of stolen credentials on the dark web and phishing attacks. Once they have access, they can escalate their privileges within Exchange and gain unauthorized access to other users' mailboxes, potentially exposing sensitive corporate information.

Microsoft has advised on-premises Exchange Server users to apply the latest cumulative updates, while users of Exchange Online are already protected by a related "service-side" fix. Although there is no evidence of active exploitation, Microsoft recommends applying the patch as soon as possible to mitigate the risk. Organizations using Exchange Server 2016 or 2019 should note that these versions reached end-of-life earlier this year, and only receive security updates through Microsoft's Extended Security Update program.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in Tech

More from Tuesday 6 October →