securityaffairs.com 6 Oct 2026, 14:09 UTC

Microsoft Patches Exchange Flaw That Could Expose Staff Mailboxes

Microsoft Patches Exchange Flaw That Could Expose Staff Mailboxes
CyberSIXT Evidence Panel
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

MICROSOFT has released out-of-band security updates for Exchange Server to fix a high-severity vulnerability tracked as CVE-2026-96940 (CVSS 8.8). The flaw stems from weak authorisation and allows an authenticated attacker to gain higher privileges on an Exchange deployment over the network. Microsoft disclosed the issue on 2 October 2026 and urged customers to apply the patches.

The advisory notes that exploitation requires authentication, but a successful attack could grant an attacker access to other users’ mailboxes within the same organisation, including reading email messages and attachments; the vulnerability does not permit access across tenant boundaries.

Affected on‑premises Exchange Server versions listed by Microsoft include: Microsoft Exchange Server Subscription Edition RTM, Exchange Server 2016 Cumulative Update 23, Exchange Server 2019 Cumulative Update 15, and Exchange Server 2019 Cumulative Update 14. Microsoft has already fixed the issue in Exchange Online, so cloud customers are not required to take action. The guidance emphasises that on-premises deployments should install the relevant security updates to remain protected.

The reporting notes the discovery by Microsoft researchers Jan Mitchell and frames the exploitation as “more likely,” underlining the urgency for administrators to apply the out-of-band fixes. While the article situates the flaw as an authentic risk for on-premises Exchange environments, it clarifies that the vulnerability does not enable cross-tenant access. No additional mitigations are described beyond applying the Microsoft updates.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline