Microsoft patches Exchange mailbox-access flaw CVE-2026-96940
Microsoft patched CVE-2026-96940, a CVSS 8.8 Exchange flaw letting authenticated users read other mailboxes in the same organization.
Microsoft released a revised September 2026 on-premises Exchange Server update, called a V2 package published October 2 by Cyber Security News and GBHackers and an out-of-band update by Help Net Security, The Hacker News, and Security Affairs, to fix CVE-2026-96940. The flaw is a weak-authorization elevation-of-privilege issue scored CVSS 8.8 that lets an authenticated attacker read other users' mailboxes and attachments in the same organization without user interaction and without crossing tenants; The Hacker News adds that this can occur over the network. Microsoft found the bug internally and is not aware of exploitation, while rating it Exploitation More Likely; Help Net Security says Microsoft warned it could be consistently exploited and that similar issues have been exploited before, and Canadian advisory AV26-1001 also does not report active exploitation. Affected builds are Subscription Edition RTM before 15.02.2562.053, Exchange 2019 CU14 before 15.02.1544.048, CU15 before 15.02.1748.053, and Exchange 2016 CU23 before 15.01.2507.075, with 2016 and 2019 limited to Period 2 Extended Security Updates through October 2026. Exchange Online is already protected, including a service-side fix Help Net Security says shipped late last week ahead of its KB article, while hybrid servers and Management Tools still need updating. GBHackers says the V2 package also fixes other flaws from external partners and internal processes and advises running the Health Checker script, rebooting, and confirming services start, and Cyber Security News says the issue is separate from CVE-2026-62911.
- CVE-2026-96940 is a CVSS 8.8 weak-authorization elevation-of-privilege flaw that Microsoft disclosed on October 2, 2026.
- An authenticated attacker can read other users' mailboxes and attachments in the same organization without user interaction; access does not cross tenants.
- Microsoft says it found the bug internally, reports no known exploitation, and rates exploitation More Likely.
- Vulnerable builds are Subscription Edition RTM before 15.02.2562.053, Exchange 2019 CU14 before 15.02.1544.048, CU15 before 15.02.1748.053, and Exchange 2016 CU23 before 15.01.2507.075.
- Exchange 2016 and 2019 patches are limited to Period 2 Extended Security Updates through October 2026.
- Exchange Online is already protected; hybrid servers and Management Tools still need the update.
- Canada's Cyber Centre issued advisory AV26-1001 on October 5, 2026, and does not report active exploitation.
- The issue is separate from CVE-2026-62911, which previously had a public authentication-relay proof of concept.
Coverage timelineoldest first · each row is one article
- · 5d agoMicrosoft Pushes New Exchange V2 Update After Discovering New Security Flaw
Cyber Security News· 67
Microsoft reissued September 2026 Exchange updates to fix CVE-2026-96940, an authenticated mailbox-access flaw scored 8.8.
- · 3d agoMicrosoft Releases Emergency Exchange Server Update to Fix CVE-2026-96940
GBHackers· 45
Microsoft issued a revised September 2026 Exchange Server update (V2) adding a fix for CVE-2026-96940 across Exchange SE, 2019, and 2016.
- · 3d ago
Vulnerabilities in this storyAll →
- CVE-2026-629118.01%Capture-Replay Authentication Bypass in Microsoft Exchange Serverpublished · microsoft exchange server
- CVE-2026-969408.8<1%Weak authorization privilege escalation in Microsoft Exchange Server