Microsoft has released out-of-band security updates for Exchange Server to fix a high-severity vulnerability tracked as CVE-2026-96940 (CVSS score of 8.8). The flaw is caused by weak authorization and can allow an authenticated attacker to gain higher privileges over a network.
Microsoft disclosed the issue on October 2, 2026, and urged customers to install the security updates. Exploitation requires authentication, but successful attacks could give attackers additional access to Exchange systems.
“An authenticated attacker who successfully exploited this vulnerability could gain unauthorized access to other users’ mailboxes within the same organization and read email messages and attachments.” reads the advisory. “The vulnerability does not allow access across tenant boundaries.”
Microsoft researchers Jan Mitchell discovered the vulnerability.
Users running affected on-premises Microsoft Exchange Server versions should install the available security updates to stay protected. Below are the impacted versions:
Microsoft has already fixed the issue in Exchange Online, so cloud customers don’t need to do anything. Customers running affected on-premises Exchange Server versions should install the relevant security updates listed by Microsoft.
It is interesting to highlight that the IT giant considers the “exploitation more likely.”
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Microsoft Exchange Server flaw)