{
  "id": 12398978,
  "title": "Microsoft Exchange flaw allows hackers to read mailboxes across an organization, so patch now",
  "url": "https://urgent.news/2026/10/06/microsoft-exchange-flaw-allows-hackers-to-read-mailboxes-across-an",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-06T14:29:56.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/microsoft-exchange-flaw-allows-hackers-to-read-mailboxes-across-an-organization-so-patch-now"
  },
  "original_language": "en",
  "account": "Microsoft has released a critical patch for a high-severity flaw in Exchange Server that could allow attackers to access other users' mailboxes within the same organization. The vulnerability, known as CVE-2026-96940, has been labeled as \"exploitation more likely\" by Microsoft, suggesting a high likelihood of abuse by cybercriminals. To exploit the flaw, attackers would need to compromise a user's credentials, which is relatively easy given the prevalence of stolen credentials on the dark web and phishing attacks. Once they have access, they can escalate their privileges within Exchange and gain unauthorized access to other users' mailboxes, potentially exposing sensitive corporate information. Microsoft has advised on-premises Exchange Server users to apply the latest cumulative updates, while users of Exchange Online are already protected by a related \"service-side\" fix. Although there is no evidence of active exploitation, Microsoft recommends applying the patch as soon as possible to mitigate the risk. Organizations using Exchange Server 2016 or 2019 should note that these versions reached end-of-life earlier this year, and only receive security updates through Microsoft's Extended Security Update program.",
  "summary": "Microsoft Exchange Server 2016 and 2019 affected, but Microsoft released a fix.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}