Exchange Server CVE-2026-96940 lets authenticated users read other mailboxes. Microsoft rates it Exploitation More Likely. Install the September 2026 v2 SU.
LiteLLM CVE-2026-93355 lets a signed JWT with an unverified email claim seize any account, including proxy_admin. No fix yet; cache-leak and SSRF CVEs patched.