Microsoft Patches High-Severity Exchange Server Flaw CVE-2026-96940
Microsoft has released out-of-band security updates to fix a high-severity vulnerability in Microsoft Exchange Server that could let an attacker escalate privileges and read other users' emails.
What Is CVE-2026-96940
The flaw, tracked as CVE-2026-96940, carries a CVSS score of 8.8. In its advisory published on October 2, 2026, Microsoft explained that the issue stems from weak authorization in Exchange Server, which allows an authenticated attacker to elevate privileges over a network.
What Attackers Can Do
By exploiting CVE-2026-96940, an authenticated attacker can gain unauthorized access to other users' mailboxes within the same organization and read their emails and attachments. Microsoft clarified that the bug does not allow access across different tenants.
Exchange Online Users Are Already Protected
Microsoft has rolled out a related service-side fix for Exchange Online. Customers using Exchange Online do not need to take any action.
Affected Exchange Server Versions
On-premises customers running the following versions should install the updates as soon as possible:
- Microsoft Exchange Server Subscription Edition RTM
- Microsoft Exchange Server 2019 Cumulative Update 15
- Microsoft Exchange Server 2019 Cumulative Update 14
- Microsoft Exchange Server 2016 Cumulative Update 23
Exploitation Risk
The vulnerability was discovered and reported by Microsoft researcher Jan Mitchell. There is currently no evidence of active exploitation in the wild. However, Microsoft has rated it "Exploitation More Likely," which means organizations should patch quickly before attackers develop working exploits.
Recent Microsoft Server Threats
The Exchange fix arrives days after Broadcom-owned Symantec reported that the China-linked Warlock threat actor is exploiting multiple Microsoft SharePoint vulnerabilities to deploy its ransomware against organizations in Portuguese- and Spanish-speaking countries.
Key Takeaway
CVE-2026-96940 gives authenticated attackers a path to read emails across an organization. Exchange Online is already protected, but on-premises administrators should apply Microsoft's out-of-band updates immediately to close the gap.