Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940)
Microsoft issued an out-of-band Exchange update for CVE-2026-96940, a same-organization mailbox read flaw.
Microsoft released an out-of-band Exchange Server update for CVE-2026-96940, a high-severity flaw that lets authenticated attackers read other users’ emails and attachments in the same organization but not across tenants. The Exchange team found it internally, says it is not aware of active exploitation, and warns the bug could be consistently exploited and that similar issues have been exploited before. A related Exchange Online service fix shipped late last week ahead of its KB article. On-prem updates cover Subscription RTM, Exchange 2019 CU14 and CU15, and Exchange 2016 CU23, and Management Tools should be updated too.
- CVE-2026-96940 lets authenticated attackers read same-organization mail and attachments.
- Access does not cross tenant boundaries, and Microsoft reports no active exploitation.
- Exchange Online received a service-side fix before documentation was published.
- On-prem coverage includes Subscription RTM, 2019 CU14 and CU15, and 2016 CU23.
Vulnerabilities mentionedAll →
- CVE-2026-969408.8<1%Weak authorization privilege escalation in Microsoft Exchange Serverpublished · Microsoft Exchange Server PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-96940 | Weak authorization privilege escalation in Microsoft Exchange Server |
Full article272 words · extracted from helpnetsecurity.com · click to collapse
Microsoft has pushed out an out-of-band security update for Exchange Server that fixes a high-severity vulnerability (CVE-2026-96940) that may allow authenticated attackers to read emails and attachments of other users in the same organization, but “does not allow access across tenant boundaries.”

CVE-2026-96940 was discovered internally and, according to the Exchange Server Team, they “are not aware of active exploitation.”
Nevertheless, Microsoft thinks that the flaw could be consistently exploited and notes that this type of vulnerability has been exploited in the past, so the company advises Exchange Server admins to update sooner rather than later.
A muddled rollout
Microsoft has deployed a related service-side fix to Exchange Online late last week, taking customers by surprise as the security updates were not immediately accompanied with a KB article explaining their content.
That misstep was soon after acknowledged by Microsoft, when the Exchange Server Team explained that the release sequence of this specific update was a bit strange because it was published ahead of its intended schedule. (They did not explain why that happened.)
The security update is available for on-prem servers running Exchange Server Subscription RTM, Exchange Server 2019 cumulative updates 14 and 15, and Exchange Server 2016 cumulative update 23.
“We recommend that customers review the deployment guidance and apply the [September 2026 v2] update at the earliest opportunity,” they said.
“Our recommendation is to install SUs on all Exchange Servers and all servers and workstations running the Exchange Management Tools to ensure compatibility between management tools clients and servers.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: