thehackernews.com 5 Oct 2026, 16:21 UTC

Microsoft Patches Exchange Flaw That Exposes Colleagues’ Mailboxes

CyberSIXT Evidence Panel
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

MICROSOFT has released out-of-band security updates for Microsoft Exchange Server to fix a high-severity vulnerability that could allow an authenticated attacker to escalate privileges and read other users’ mail within the same organisation. The flaw is tracked as CVE-2026-96940 and is rated 8.8 on the CVSS scale. Microsoft describes it as weak authorisation that enables an authenticated attacker to gain access to colleagues’ mailboxes by exploiting improper access controls; cross-tenant access is not possible.

The advisory states that Exchange Online has already received a related service-side fix, so online customers do not need to act. On-premises Exchange Server users are advised to apply the updates to stay protected. Affected on-premises products are listed as: Microsoft Exchange Server Subscription Edition RTM; Microsoft Exchange Server 2016 Cumulative Update 23; Microsoft Exchange Server 2019 Cumulative Update 15; and Microsoft Exchange Server 2019 Cumulative Update 14.

Microsoft credits Jan Mitchell of Microsoft Research for discovering and reporting the flaw. Although there is no evidence of active exploitation in the wild, Microsoft has given the vulnerability an Exploitability assessment of “Exploitation More Likely,” underscoring the urgency for patching.

The disclosure comes soon after warnings that the Warlock threat actor has been exploiting vulnerabilities in SharePoint to deploy ransomware, highlighting a broader pattern of targeted exploits against corporate environments.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline