Protect.Computer
NEWS

Exchange Server Flaw Lets Users Read Others' Mailboxes

· 1 min read · Data hijack
Exchange Server Flaw Lets Users Read Others' Mailboxes

Microsoft has released out-of-band security updates for a high-severity flaw in Microsoft Exchange Server, tracked as CVE-2026-96940 and rated 8.8 on the CVSS scale. Microsoft’s advisory, published on October 2, 2026, describes it as weak authorization that lets an authenticated attacker elevate privileges over a network.

In practice, an attacker who already has a valid login can use the bug to reach other users’ mailboxes in the same organization and read email messages and attachments. The flaw does not allow access across tenants. Microsoft has already deployed a related service-side fix to Exchange Online, so cloud customers need to do nothing. There is no evidence of exploitation in the wild so far, but Microsoft rates it “Exploitation More Likely,” so on-premises administrators should not wait. Microsoft credited researcher Jan Mitchell with the discovery.

How to check if you’re affected

Affected products are on-premises Microsoft Exchange Server installations; Exchange Online is not affected. Affected versions are:

  • Exchange Server Subscription Edition RTM
  • Exchange Server 2016 Cumulative Update 23
  • Exchange Server 2019 Cumulative Update 15
  • Exchange Server 2019 Cumulative Update 14

Run Get-ExchangeServer | Format-List Name,AdminDisplayVersion in the Exchange Management Shell to see which version each server is running, then apply Microsoft’s update for CVE-2026-96940 from the advisory below.

Sources

Related reading