Microsoft patches high-severity Exchange Server flaw that exposes other users' mailboxes
Microsoft released an out-of-band Exchange Server update fixing CVE-2026-96940, a high-severity privilege-escalation flaw that lets an authenticated attacker read mailboxes across the same organization. Exchange Online is already fixed; on-premises customers must patch.
The vulnerability, tracked as CVE-2026-96940, is described by the National Vulnerability Database as a "weak authorization in Microsoft Exchange Server [that] allows an authenticated attacker to elevate privileges over a network." Microsoft rated it 8.8 out of 10, or high severity, and warned in its advisory that it can be abused to gain unauthorized access to inboxes belonging to other people within the same organization. The flaw does not allow cross-tenant access.
Exploitation requires authenticated access to Exchange first, so an attacker needs valid credentials for a low-privileged account before escalating. TechRadar reported that this is not a difficult hurdle, because credentials can be bought on dark-web markets or harvested through phishing and infostealer malware. From that foothold, an attacker could reach the mail of more senior staff. Corporate mailboxes hold contracts, invoices, confidential documents and internal discussions that can feed follow-on Business Email Compromise attacks.
Microsoft's disclosed attack scenario stops at privilege escalation inside Exchange and unauthorized mailbox access. The company has not said the flaw grants administrator or SYSTEM-level rights on the underlying Windows server.
Exchange Online customers are already protected, Microsoft said, because it deployed a related service-side fix. Organizations running on-premises Exchange Server products should upgrade to the latest version. The affected versions are Exchange Server Subscription Edition RTM, Exchange Server 2016 Cumulative Update 23, Exchange Server 2019 Cumulative Update 15 and Exchange Server 2019 Cumulative Update 14.
Microsoft said it has no evidence the flaw has been exploited in the wild, and at the time of the report the US Cybersecurity and Infrastructure Security Agency had not listed it in its Known Exploited Vulnerabilities catalog. The company nevertheless labeled the vulnerability "exploitation more likely" and urged customers to apply the fix as soon as possible.
Both Exchange Server 2016 and Exchange Server 2019 reached end of support last year. Microsoft said the new security updates are available only to organizations enrolled in its Period 2 Extended Security Update program, which covers updates released between May and the end of October 2026. Organizations that have not enrolled are being urged to migrate to Exchange Server Subscription Edition if they want to keep receiving security fixes.
The patch was issued on October 2 as part of the September 2026 V2 Exchange Server Security Updates. The original September updates were released on September 8, and Microsoft said the main difference between the two versions is the fix for CVE-2026-96940. The company confirmed it was publishing the update ahead of its intended schedule without elaborating further. Administrators are advised to run Microsoft's Exchange Server Health Checker after installation to verify that the update was applied successfully and to determine whether any additional action is required.