Microsoft Exchange privilege escalation advisory
π Microsoft issued out-of-band updates for a high-severity flaw in Microsoft Exchange Server that can allow an authenticated attacker to elevate privileges and access other users' mailboxes within the same organization. Tracked as CVE-2026-96940 with a CVSS score of 8.8, Microsoft applied a service-side fix for Exchange Online, while on-premises customers must install provided updates for specified Exchange Server builds. The company named researcher Jan Mitchell as the reporter and rated exploitability as "Exploitation More Likely."
