Skip to content
cve — cve-2026-96940

grep -rl "CVE-2026-96940" ./articles

CVE-2026-96940

Microsoft published an out-of-band advisory for CVE-2026-96940, an authorisation flaw scored 8.8. An attacker needs valid credentials for any mailbox in the organisation; from there they can read other people's messages and attachments. Exchange Online was mitigated server-side. On-premises stays exposed until an administrator installs the update.

1 article — 2026-10-06

Authoritative record

Root Notes reports on this identifier; it does not maintain it. For the vendor advisory, the affected versions and the scoring, NVD and MITRE hold the primary records.

Our coverage

../cve — every identifier we have covered