VMTech
Discuss a project →

Microsoft fixes high-severity Exchange mailbox access flaw

Microsoft fixes high-severity Exchange mailbox access flaw

Microsoft has released out-of-band security updates for CVE-2026-96940, a high-severity privilege-escalation vulnerability in Microsoft Exchange Server. The flaw carries a CVSS score of 8.8 and could let an authenticated attacker gain unauthorized access to other users’ mailboxes within the same organization.

Successful exploitation would allow the attacker to read email messages and attachments belonging to other users. Microsoft said the weakness stems from insufficient authorization in Exchange Server and can be exploited over a network by an attacker who is already authenticated.

On-premises Exchange versions require updates

The affected products are Microsoft Exchange Server Subscription Edition RTM, Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 15, and Microsoft Exchange Server 2019 Cumulative Update 14. Organizations running any of these on-premises releases should install Microsoft’s updates.

The issue does not enable cross-tenant access. Microsoft has also deployed a related service-side fix for Exchange Online, meaning Exchange Online customers do not need to take action for this vulnerability.

Microsoft marks exploitation as more likely

Microsoft credited researcher Jan Mitchell with discovering and reporting CVE-2026-96940. The company said it has not found evidence that the vulnerability has been weaponized in the wild. Even so, it assigned an Exploitability Assessment of Exploitation More Likely.

That assessment raises the urgency for administrators of self-managed Exchange infrastructure. A valid account is required, but mailbox access can expose internal correspondence, attachments, and other sensitive material available to targeted users.

What security teams should do

Teams should first establish whether any affected Exchange Server builds remain in service, including less visible systems used for legacy mail workflows. They should then apply the out-of-band updates through their established change-management process and confirm that the patched versions are operating as expected.

Because the vulnerability concerns authenticated access, organizations should also review privileged and unusual Exchange account activity as part of their normal monitoring. The immediate business implication is clear: enterprises operating affected on-premises Exchange Server versions should treat patch deployment as a priority to reduce the risk of internal mailbox exposure.

#cybersecurity#microsoft#exchange#patchmanagement
Open analytics
On the site 0 views
min read 3 05.10.2026
Instagram

Microsoft fixes high-severity Exchange mailbox access flaw

Open the post on Instagram ↗