CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely
Microsoft patched CVE-2026-96940, which lets authenticated attackers read other Exchange mailboxes in the same organization.
Microsoft released out-of-band updates for on-premises Exchange Server to fix CVE-2026-96940 (CVSS 8.8), a weak-authorization flaw disclosed on October 2, 2026. An authenticated attacker can gain higher privileges and read other users' mailboxes and attachments inside the same organization, but not across tenants. Affected versions are Subscription Edition RTM, Exchange Server 2016 CU23, and Exchange Server 2019 CU14 and CU15. Exchange Online is already patched; Microsoft rates exploitation as more likely, with no confirmed in-the-wild attacks.
- CVE-2026-96940 is CVSS 8.8 and requires authentication.
- Attackers can read other users' mail and attachments in the same organization.
- Affected: Subscription Edition RTM, Exchange 2016 CU23, Exchange 2019 CU14 and CU15.
- Exchange Online is already fixed; Microsoft rates exploitation more likely.
Vulnerabilities mentionedAll →
- CVE-2026-969408.8<1%Weak authorization privilege escalation in Microsoft Exchange Serverpublished · Microsoft Exchange Server PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-96940 | Weak authorization privilege escalation in Microsoft Exchange Server |
Full article252 words · extracted from securityaffairs.com · click to collapse

Microsoft released emergency updates for Exchange Server to fix CVE-2026-96940, a high-severity flaw that can let attackers gain higher privileges.
Microsoft has released out-of-band security updates for Exchange Server to fix a high-severity vulnerability tracked as CVE-2026-96940 (CVSS score of 8.8). The flaw is caused by weak authorization and can allow an authenticated attacker to gain higher privileges over a network.
Microsoft disclosed the issue on October 2, 2026, and urged customers to install the security updates. Exploitation requires authentication, but successful attacks could give attackers additional access to Exchange systems.
“An authenticated attacker who successfully exploited this vulnerability could gain unauthorized access to other users’ mailboxes within the same organization and read email messages and attachments.” reads the advisory. “The vulnerability does not allow access across tenant boundaries.”
Microsoft researchers Jan Mitchell discovered the vulnerability.
Users running affected on-premises Microsoft Exchange Server versions should install the available security updates to stay protected. Below are the impacted versions:
- Microsoft Exchange Server Subscription Edition RTM
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Update 15
- Microsoft Exchange Server 2019 Cumulative Update 14
Microsoft has already fixed the issue in Exchange Online, so cloud customers don’t need to do anything. Customers running affected on-premises Exchange Server versions should install the relevant security updates listed by Microsoft.
It is interesting to highlight that the IT giant considers the “exploitation more likely.”
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Microsoft Exchange Server flaw)