One working mailbox password let an Exchange user read everyone else's mail, and the cloud was fixed before anyone was told
2026-10-06Security
Microsoft published an out-of-band advisory for CVE-2026-96940, an authorisation flaw scored 8.8. An attacker needs valid credentials for any mailbox in the organisation; from there they can read other people's messages and attachments. Exchange Online was mitigated server-side. On-premises stays exposed until an administrator installs the update.