Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
Microsoft patched CVE-2026-96940, an Exchange flaw that lets authenticated attackers read other users' mailboxes.
Microsoft released out-of-band updates for CVE-2026-96940, a CVSS 8.8 authorization flaw in on-premises Exchange Server. An authenticated attacker can elevate privileges over the network and read other users' messages and attachments in the same organization, but not across tenants. Exchange Online already received a service-side fix. Affected builds are Subscription Edition RTM, Exchange 2016 CU23, and Exchange 2019 CU14 and CU15. Microsoft reports no exploitation in the wild but rates it Exploitation More Likely.
- CVE-2026-96940 scores CVSS 8.8 for weak Exchange authorization.
- Authenticated users can read other mailboxes in the same organization.
- Exchange Online is patched; on-premises servers must install updates.
- No in-the-wild exploitation, but Microsoft says exploitation is more likely.
Vulnerabilities mentionedAll →
- CVE-2026-969408.8<1%Weak authorization privilege escalation in Microsoft Exchange Serverpublished · Microsoft Exchange Server PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-96940 | Weak authorization privilege escalation in Microsoft Exchange Server |
Full article295 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananOct 05, 2026Vulnerability / Email Security
Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions.
The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system.
"Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network," Microsoft said in an advisory released on October 2, 2026.
The Windows maker said an authenticated attacker can exploit this flaw to gain unauthorized access to other users' mailboxes within the same organization and read email messages and attachments. However, the vulnerability does not allow cross-tenant access.
Microsoft has already deployed a "related service-side fix" to Exchange Online to address the issue. As a result, Exchange Online customers are not required to take any action.
Users of affected on-premises Microsoft Exchange Server products are advised to install the updates to stay protected. The following versions are impacted -
- Microsoft Exchange Server Subscription Edition RTM
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Update 15
- Microsoft Exchange Server 2019 Cumulative Update 14
Redmond has credited Microsoft researcher Jan Mitchell with discovering and reporting the flaw. Although there is no evidence of the flaw being weaponized in the wild, Microsoft has tagged it with an Exploitability assessment of "Exploitation More Likely," making it essential that users move quickly to apply the fixes.
The disclosure comes days after Broadcom-owned Symantec warned that the China-linked Warlock actor is exploiting multiple vulnerabilities in Microsoft SharePoint to deploy its namesake ransomware in attacks targeting organizations in Portuguese- and Spanish-speaking countries.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: