
Microsoft Exchange Flaw Let Attackers Read Other Mailboxes
Microsoft shipped emergency Exchange Server updates to close CVE-2026-96940, which let authenticated attackers open other users’ mail and attachments.
Microsoft has published out-of-band security updates for Microsoft Exchange Server to close a high-severity weakness that could allow an authenticated attacker to read other people's email. The vulnerability, identified as CVE-2026-96940, carries a CVSS severity score of 8.8 out of 10. An out-of-band update is one released outside the regular monthly patch schedule because the risk is serious enough to demand immediate action.
According to Microsoft's advisory from October 2, 2026, the flaw stems from weak authorization in Exchange Server. Authorization is the process that decides what a signed-in user is allowed to do. An authenticated attacker, meaning someone who already has valid credentials for any account in the organisation, can exploit this weakness over the network. Once exploited, the attacker can elevate their privileges and gain unauthorised access to other users' mailboxes within the same organisation. They can read email messages and attachments, but the vulnerability does not allow access across different tenants, so one company cannot reach another company's mail.
Microsoft has already deployed a related service-side fix to Exchange Online, its hosted email service. Exchange Online customers do not need to take any action because the fix is applied automatically on Microsoft's infrastructure. However organisations running Exchange Server on their own hardware (on-premises) must install the updates themselves. The affected versions are Microsoft Exchange Server Subscription Edition RTM, Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 15, and Microsoft Exchange Server 2019 Cumulative Update 14. A cumulative update is a package that includes all previous fixes for that version, so installing the latest one brings the server up to date.
Microsoft credited its own researcher, Jan Mitchell, with discovering and reporting the flaw. Although Microsoft says there is no evidence that the vulnerability has been used in real attacks yet, it assigned an Exploitability assessment of "Exploitation More Likely." That label means the company believes attackers will probably develop a working exploit, so administrators should move quickly. The fact that an attacker only needs a valid account, not administrator rights, raises the practical risk: many organisations have user accounts that could be phished or stolen, and once one account is compromised, an attacker could use this flaw to reach other people's mail.
For IT teams, the immediate step is to review which Exchange Server version and cumulative update are in use and apply the out-of-band update without delay. After patching, teams should examine mailbox permission settings and audit logs for any unusual access to mailboxes that the logged-in user should not have opened. Enforcing multi-factor authentication also reduces the chance that a stolen password alone can be used to start an attack. Since Exchange Online is already protected, organisations with hybrid setups should confirm that their on-premises servers are patched and that any connectors or synchronisation tools do not expose the vulnerable service to the internet without need.
Keeping on-premises Exchange servers current is a continuous job, not a one-time patch. Microsoft's regular security update guide and the Exchange Server health page list the supported cumulative updates and known issues. Organisations that manage on-premises Exchange servers should confirm which cumulative update is installed and track these out-of-band patches as part of security hygiene; AEU-I, our security-first IT and infrastructure consulting service, helps teams plan and verify exactly this kind of patch and access-control work. Subscribing to vendor security notifications and testing updates in a staging environment before production rollout are also standard practices that reduce downtime and exposure.
How to Protect Yourself
- If your company uses Microsoft Exchange Server, ask your IT team whether your version is affected and whether they have installed the emergency update.
- If you manage an Exchange server, download and apply the out-of-band update for your version immediately, then restart the required services.
- Turn on multi-factor authentication for all email accounts so a stolen password alone cannot open someone's mailbox.
- Review mailbox permission settings and audit logs to look for any account that has opened mailboxes it should not have access to.
- Subscribe to Microsoft's security update notifications so your team learns about emergency patches as soon as they are released.
Vulnerabilities & Fixes
- CVE-2026-96940 A high-severity authorization weakness in Microsoft Exchange Server fixed by Microsoft's out-of-band security updates. View the fix & details →
Terms Explained
- authenticated attacker A person who has already signed in with a valid username and password, so the system sees them as a real user.
- authorization The rules that decide what a signed-in user is allowed to see and do.
- CVSS A standard scoring system that rates how serious a security weakness is, from 0 to 10.
- out-of-band update A security fix released outside the regular monthly schedule because the problem is urgent.
- Exchange Server Microsoft's email and calendar software that companies run on their own servers.
- Exchange Online Microsoft's hosted email service that runs in the cloud and is updated automatically.
- on-premises Software or servers located inside an organisation's own building rather than in a cloud provider's data centre.
- cumulative update A package of all previous fixes for a software version, so installing the latest one brings the system fully up to date.