Microsoft has released September 2026 V2 security updates to fix an Exchange Server flaw that lets authenticated attackers access other users’ mailboxes within the same organization. Tracked as CVE-2026–96940, the vulnerability could expose email messages and attachments, making it a serious concern for businesses running Exchange on-premises. The flaw involves weak authorization, allowing an attacker with authenticated access to gain privileges over a network. Public vulnerability records list a CVSS score of 8.8. Unlike attacks that require someone to open a malicious file, exploitation does not require user interaction. The reported mailbox access does not extend across tenant boundaries. Microsoft said its own teams...
Læs hele artiklen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!