Skip to main content
CybersecurityVulnerability Management

Microsoft Exchange Flaw Exposes Mailboxes to Authenticated Attackers

Rows of computer servers and networking equipment in a neutral-toned server room or data center interior.

"Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network," Microsoft said in an advisory released on October 2, 2026.

Microsoft's October 2 advisory and the urgency it conveys

On October 2, 2026, Microsoft published an out-of-band security update to address a high-severity flaw in Microsoft Exchange Server tracked as CVE-2026-96940 and rated 8.8 on the CVSS scale. Microsoft described the issue as a weak authorization vulnerability that allows an authenticated attacker to elevate privileges across a network. Although Microsoft reported no evidence the flaw has been weaponized in the wild, it attached an Exploitability assessment of "Exploitation More Likely," and said that this assessment makes it essential that users move quickly to apply the fixes.

What CVE-2026-96940 lets an attacker do

According to Microsoft, an authenticated attacker exploiting CVE-2026-96940 can gain unauthorized access to other users' mailboxes within the same organization and read email messages and attachments. Microsoft explicitly noted the flaw does not permit cross-tenant access. The vendor has characterized the root cause as weak authorization in Exchange Server.

Affected on‑premises Exchange Server versions

Microsoft released out-of-band updates for affected on-premises products and advised administrators to install them. The versions Microsoft listed as impacted are:

  • Microsoft Exchange Server Subscription Edition RTM
  • Microsoft Exchange Server 2016 Cumulative Update 23
  • Microsoft Exchange Server 2019 Cumulative Update 15
  • Microsoft Exchange Server 2019 Cumulative Update 14

Microsoft's guidance to users of those on‑premises products is to install the updates to stay protected.

Exchange Online — Microsoft applied a server-side fix

Microsoft said it has already deployed a "related service-side fix" to Exchange Online. As a result, Microsoft stated Exchange Online customers are not required to take any action in response to this advisory. The split treatment — a service-side mitigation for Exchange Online and patches for on-premises servers — is the action Microsoft published to close the gap described in the advisory.

Context: Symantec warning about Warlock and SharePoint attacks

The disclosure of CVE-2026-96940 came days after Broadcom-owned Symantec warned that the China-linked Warlock actor is exploiting multiple vulnerabilities in Microsoft SharePoint to deploy Warlock ransomware. Symantec said those attacks targeted organizations in Portuguese- and Spanish-speaking countries. Microsoft’s Exchange advisory and Symantec’s warning arrived within the same short time frame, underscoring concurrent activity affecting Microsoft server products.

What this means for technologists, affected enterprises, and adversaries

  • Technologists and security teams: Teams responsible for on‑premises Exchange should prioritize installation of Microsoft’s out‑of‑band updates for the listed builds. Exchange Online tenants, Microsoft said, do not need to take action because of the service-side fix.
  • Affected enterprises and procurement leaders: Organizations running the specified on‑premises Exchange versions must schedule and validate patching to prevent unauthorized mailbox access; Microsoft’s "Exploitation More Likely" assessment makes speed a factor in risk reduction.
  • Adversaries and threat actors: Microsoft reported no evidence of active exploitation at publication, but its exploitability rating and the contemporaneous Symantec warnings about SharePoint-targeted ransomware highlight an elevated incentive for attackers to seek and weaponize similar vulnerabilities.

Microsoft credited researcher Jan Mitchell with discovering and reporting the flaw. With Exchange Online protected by a related server-side change and on-premises administrators instructed to apply updates, the immediate path to mitigation is clear. Whether attackers will attempt to weaponize CVE-2026-96940 remains unobserved; Microsoft’s own "Exploitation More Likely" assessment and the recent SharePoint-focused activity reported by Symantec mean defenders have a narrow window to act.

Original story: Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes — The Hacker News