Microsoft issued an out-of-band Exchange Server fix for CVE-2026-96940, a bug letting signed-in attackers read colleagues' mail and attachments. The company expects the flaw to be consistently exploitable, so on-premises admins have good reason to install it ahead of the next maintenance window.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence50
Microsoft will allow only scripts from its own CDN domains during Entra ID browser sign-ins under a Content Security Policy enforced from mid-October 2026. Browser extensions and tools that inject code into the sign-in page will stop working as the rollout completes in late October.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence70
Microsoft shipped 22 updates, six of them scored 10.0, mostly in Entra ID, Exchange Online and Azure. Fixed server-side is not the same as verified in your tenant.
Perspective Coverage
5 publishers
- Builder
- Builder 20%
- Operator
- Operator 65%
- Investor
- Investor 15%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+40
- Incentives55
- Confidence55
Microsoft has tracked intrusions since May in which callers posing as IT told employees a passkey update was due, then steered them to a phishing page or a device-code prompt. The enrollment step is where the chain starts.
Reality
- Evidence55
- Adoption35
- Hype gap−5
- Incentives60
- Confidence58
KnowBe4's Threat Lab logged the messages across July and August 2026. None of them needed a stolen password to look like mail from HR or accounting, and a single send addressed 900 recipients. The report landed September 10.
Reality
- Evidence57
- Adoption54
- Hype gap+14
- Incentives68
- Confidence56
Microsoft has tracked this since May 2026. First contact lands on an unmanaged personal phone, and the attacker's own authenticator outlives the stolen session, so tenant telemetry only starts after the account is already lost.
Reality
- Evidence55
- Adoption45
- Hype gap−10
- Incentives65
- Confidence58
Microsoft's initial read on EX1467029 blames its own anti-spam protections for part of the impact, and with no root cause, region list or fix time in the alert, queue depth is the only scoping signal admins have.
Reality
- Evidence55
- Adoption30
- Hype gap0
- Incentives55
- Confidence58
Two Teams faults are open at once: Mac users cannot join calls, and Windows clients can take up to two minutes to launch. With the code-change theory withdrawn, there is nothing to plan a fix date around.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+8
- Incentives62
- Confidence52
ReliaQuest's tests show Exchange Online accepts unauthenticated mail when the visible From header matches the tenant domain and the SMTP envelope sender is left empty. Forty percent of those messages went to senior leaders.
Reality
- Evidence48
- Adoption42
- Hype gap+10
- Incentives65
- Confidence45
Microsoft traced the failure to recent changes it had made to the service and spent the day testing whether reverting them would help. For anyone mapping dependencies, it was a cheap rehearsal.
Reality
- Evidence45
- Adoption40
- Hype gap−15
- Incentives70
- Confidence55
Island's write-up describes an adversary-in-the-middle proxy that hands passwords, push approvals and SMS codes to real Microsoft servers, then keeps the cookie Microsoft issues. Origin binding is the only listed control that breaks it.
Reality
- Evidence48
- Adoption40
- Hype gap+18
- Incentives66
- Confidence47