Published: 10/06/26
Tuesday starts with email. Microsoft shipped an out-of-band Exchange update on Friday for a bug that lets any logged-in user read other people’s mailboxes, and servers that installed September’s update still need it. Also on the desk: a forgotten Rejetto file server can now be taken over with a public exploit, Dell’s own server-update tool needs an update, and Denmark found out the hard way what a partner’s valid login can pull in ten days.
Lead Story
One phished login could read any inbox on on-prem Exchange — install the reissued update
CVE-2026-96940 lets an authenticated user open other mailboxes in the same Exchange organization, attachments included. Microsoft found it internally, says it is not exploited, and rates it “Exploitation More Likely.” The fix is the September 2026 V2 Security Update, released October 2. The original September update does not include it. Exchange Online is already fixed. Exchange 2016 and 2019 get it only with Period 2 ESU.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Why it matters: Any phished account becomes a key to the CFO’s inbox. The patch is the only control Microsoft has offered.
Also Worth Your Attention
Rejetto file servers are being probed — upgrade HFS before the scans turn into break-ins
CVE-2026-61500 lets an attacker rebuild HFS’s cookie-signing key from login replies, forge an admin session and run code. It affects 3.0.0 through 3.2.0. A public exploit landed September 30, and VulnCheck saw probing from October 1. Move to 3.3.4.
Why it matters: These boxes sit outside the patch system, and an older HFS bug already made CISA’s exploited list.
Dell’s server update tool needs its own update — move DSU to 2.3.0.0
CVE-2026-86360 is a path traversal in Dell System Update that Dell says can give an unauthenticated remote attacker root. Four more highs ship in the same fix. Upgrade DSU to 2.3.0.0 and update the version pinned in automation. Not reported exploited.
Why it matters: The tool that touches every PowerEdge with root rights is the blast radius.
A partner’s login pulled 8.8 million Danish records — check what your vendor keys can pull
Someone misused a small Danish company’s legitimate access to the national CPR register for about ten days in September, running automated lookups that pulled names, addresses and ID numbers for about 8.8 million people. Spotted October 2, announced October 5.
Why it matters: Real credentials and correct permissions. Only the volume was wrong. Do you alert on partner-key volume?
Slack paste: Tuesday brief — on-prem Exchange needs the Sept 2026 V2 SU (Oct 2) on every server and Management Tools host; any logged-in user can read other mailboxes until then (CVE-2026-96940). Rejetto HFS to 3.3.4 or offline (public PoC, scanning since Oct 1). Dell System Update to 2.3.0.0. Denmark CPR: 8.8M records via one partner login — alert on partner/API key volume.
Go Deeper
Identity & Access Management → · Cybersecurity Tools →
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.