Microsoft Exchange flaw allows hackers to read an organization’s mailboxes, so patch now
- Microsoft troubleshooting for CVE-2026-96940, a high-severity Exchange privilege escalation flaw
- Attackers with compromised user credentials could access other employees’ mailboxes and emails
- No active exploit was reported, but Microsoft rated the vulnerability as “exploit most likely.”
Microsoft has released an urgent update for Exchange Server that fixes a high-severity flaw that could wreak havoc on email users.
The company patched CVE-2026-96940, a “weak authorization in Microsoft Exchange Server [that] allows an authenticated attacker to elevate privileges across a network,” according to the National Vulnerabilities Database (NVD).
According to Microsoft’s advisory, the bug, which was given a severity rating of 8.8/10 (high), can be abused to gain unauthorized access to the inboxes of people within the same organization.
Latest videos ofTechnologyRadar
In theory, threat actors who obtained credentials from a low-privileged Exchange user could exploit CVE-2026-96940 to escalate their privileges within Exchange and then read sensitive emails and attachments belonging to other people who work for the same organization.
However, the bug cannot be exploited for cross-tenant access.
To exploit the vulnerability, the threat actor must have authenticated access beforehand. However, this is not a major obstacle for attackers, as they can easily purchase login credentials on the dark web or use phishing to deploy an information stealer capable of extracting these secrets.
Therefore, even an “ordinary” employee email account can be enough to establish a foothold, escalate privileges, and access inboxes belonging to higher levels within an organization.
At that point, vulnerability becomes very valuable. Corporate email accounts can contain sensitive documents, contracts, invoices, internal discussions, and other sensitive information, which attackers can then use for follow-up attacks such as Business Email Compromise (BEC).
It is worth emphasizing that CVE-2026-96940 is not known to grant administrator or SYSTEM-level privileges on the underlying Windows server. Instead, the attack scenario revealed by Microsoft focuses on escalating privileges within Exchange and gaining unauthorized access to other users’ mailboxes.
Exchange Online users are already protected, Microsoft explained, as it implemented a related “service-side” solution. However, those using on-premises Microsoft Exchange Server products should update to the latest version to avoid being attacked.
Here is a list of the affected versions:
– Microsoft Exchange Server RTM Subscription Edition
– Microsoft Exchange Server 2016 Cumulative Update 23
– Microsoft Exchange Server 2019 Cumulative Update 15
– Microsoft Exchange Server 2019 Cumulative Update 14
Microsoft says there is no evidence that the flaw has been abused in the wild, and as of press time, the US Cybersecurity and Infrastructure Security Agency (CISA) does not include it in its catalog of known exploited vulnerabilities (KEV). However, the Windows maker called the bug “most likely to exploit”, suggesting that cybercriminals could try to exploit it and warning users to apply the provided fix as soon as possible.
It’s also worth mentioning that both Exchange Server 2016 and Exchange Server 2019 reached their end of support last year. Microsoft said these latest security updates are only available to organizations enrolled in its Period 2 Extended Security Update (ESU) program.
The program gives eligible Exchange Server 2016 and 2019 customers access to security updates released between May and the end of October 2026. Organizations that have not enrolled are encouraged to migrate to Exchange Server Subscription Edition (SE) if they want to continue receiving the latest security fixes.
unusual release
Microsoft issued the patch on October 2, as part of its September 2026 Exchange Server V2 security updates. The original September updates were released on September 8 and the software giant added that the main difference between these two versions is the fix for CVE-2026-96940.
While releasing the patch, he confirmed that he was moving it “ahead of his planned schedule,” without giving further details. Perhaps labeling it as “most likely exploit” is enough, especially since the company urged customers to review its deployment guide and apply the update as soon as possible.
After installing the update, administrators are also recommended to run Microsoft’s Exchange Server Health Checker. The tool can check if the security update was installed correctly and determine if any additional action is required.
Through Hacker News
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.



Post Comment