Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940) - Help Net Security
Microsoft has pushed out an out-of-band security update for Exchange Server that fixes a high-severity vulnerability (CVE-2026-96940) that may allow authenticated attackers to read emails and attachments of other users in the same organization, but CVE-2026-96940 was discovered internally and, according to the Exchange Server Team, they Nevertheless, Microsoft thinks that the flaw could be consistently exploited and notes that this type of vulnerability has been exploited in the past, so the company advises Exchange Server admins to update sooner rather than later.

Microsoft has pushed out an out-of-band security update for Exchange Server that fixes a high-severity vulnerability (CVE-2026-96940) that may allow authenticated attackers to read emails and attachments of other users in the same organization, but CVE-2026-96940 was discovered internally and, according to the Exchange Server Team, they Nevertheless, Microsoft thinks that the flaw could be consistently exploited and notes that this type of vulnerability has been exploited in the past, so the company advises Exchange Server admins to update sooner rather than later.
Microsoft has deployed a related service-side fix to Exchange Online late last week, taking customers by surprise as the security updates were not immediately accompanied with a KB article explaining their content.
That misstep was soon after acknowledged by Microsoft, when the Exchange Server Team explained that the release sequence of this specific update was a bit strange because it was published ahead of its intended schedule.
(They did not explain why that happened.) The security update is available for on-prem servers running Exchange Server Subscription RTM, Exchange Server 2019 cumulative updates 14 and 15, and Exchange Server 2016 cumulative update 23.
What happened
Microsoft has pushed out an out-of-band security update for Exchange Server that fixes a high-severity vulnerability (CVE-2026-96940) that may allow authenticated attackers to read emails and attachments of other users in the same organization, but CVE-2026-96940 was discovered internally and, according to the Exchange Server Team, they Nevertheless, Microsoft thinks that the flaw could be consistently exploited and notes that this type of vulnerability has been exploited in the past, so the company advises Exchange Server admins to update sooner rather than later.
Microsoft has deployed a related service-side fix to Exchange Online late last week, taking customers by surprise as the security updates were not immediately accompanied with a KB article explaining their content.
That misstep was soon after acknowledged by Microsoft, when the Exchange Server Team explained that the release sequence of this specific update was a bit strange because it was published ahead of its intended schedule.
Who is affected
(They did not explain why that happened.) The security update is available for on-prem servers running Exchange Server Subscription RTM, Exchange Server 2019 cumulative updates 14 and 15, and Exchange Server 2016 cumulative update 23.
Attribution
Help Net Security: Microsoft has pushed out an out-of-band security update for Exchange Server that fixes a high-severity vulnerability (CVE-2026-96940) that may allow authenticated attackers to read emails and attachments of other users in the same organization, but “does not allow access across tenant boundaries.” CVE-2026-96940 was discovered internally and, according to the Exchange Server Team, they “are not aware of active exploitation.” Nevertheless, Microsoft thinks that the flaw could be consistently exploited and notes that this type of vulnerability has been exploited in the past, so the company advises Exchange Server admins to update sooner rather than later.
What to watch next
Watch for additional victim details, indicators of compromise and follow-on exploitation reports.
Watch for revised vendor guidance, fixed versions and mitigation updates.