Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions.

Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions.
The vulnerability, tracked as CVE-2026-96940 , is rated 8.8 on the CVSS scoring system.
Microsoft said in an advisory released on October 2, 2026.
The following versions are impacted - Redmond has credited Microsoft researcher Jan Mitchell with discovering and reporting the flaw.
The disclosure comes days after Broadcom-owned Symantec warned that the China-linked Warlock actor is exploiting multiple vulnerabilities in Microsoft SharePoint to deploy its namesake ransomware in attacks targeting organizations in Portuguese- and Spanish-speaking countries.
The Windows maker said an authenticated attacker can exploit this flaw to gain unauthorized access to other users' mailboxes within the same organization and read email messages and attachments.
As a result, Exchange Online customers are not required to take any action.
Users of affected on-premises Microsoft Exchange Server products are advised to install the updates to stay protected.
Although there is no evidence of the flaw being weaponized in the wild, Microsoft has tagged it with an Exploitability assessment of making it essential that users move quickly to apply the fixes.
Microsoft has already deployed a to Exchange Online to address the issue.
What happened
Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions.
The vulnerability, tracked as CVE-2026-96940 , is rated 8.8 on the CVSS scoring system.
Microsoft said in an advisory released on October 2, 2026.
What changed
The following versions are impacted - Redmond has credited Microsoft researcher Jan Mitchell with discovering and reporting the flaw.
The disclosure comes days after Broadcom-owned Symantec warned that the China-linked Warlock actor is exploiting multiple vulnerabilities in Microsoft SharePoint to deploy its namesake ransomware in attacks targeting organizations in Portuguese- and Spanish-speaking countries.
Who is affected
The Windows maker said an authenticated attacker can exploit this flaw to gain unauthorized access to other users' mailboxes within the same organization and read email messages and attachments.
As a result, Exchange Online customers are not required to take any action.
Why it matters
Users of affected on-premises Microsoft Exchange Server products are advised to install the updates to stay protected.
Technical details
Although there is no evidence of the flaw being weaponized in the wild, Microsoft has tagged it with an Exploitability assessment of making it essential that users move quickly to apply the fixes.
Response
Microsoft has already deployed a to Exchange Online to address the issue.
Attribution
The Hacker News: Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions.
What to watch next
Watch for additional victim details, indicators of compromise and follow-on exploitation reports.
Watch for revised vendor guidance, fixed versions and mitigation updates.