Microsoft Exchange Server Flaw CVE-2026-96940 Allows Privilege Escalation
Out-of-band updates address high-severity vulnerability affecting authenticated users

Key Takeaways
- Microsoft released out-of-band security updates for CVE-2026-96940, a high-severity Exchange Server vulnerability.
- The flaw involves weak authorization that could allow authenticated attackers to elevate privileges.
- Successful exploitation could allow access to other users' mailboxes, risking data exfiltration.
Related Security News

Active scanning detected for critical Rejetto HFS vulnerability
Security researchers and threat actors are actively scanning the internet for Rejetto HTTP File Server (HFS) instances exposed to the internet. The activity targets a critical vulnerability, tracked as CVE-2026-61500, which stems from a weak signing key. Successful exploitation could allow session forgery, account takeover, and remote code execution. No official patch has been confirmed in the reporting, and the CVE assignment is noted to fall outside typical assignment windows, requiring independent verification.



