Critical Microsoft Exchange Vulnerability Allows Unauthorized Mailbox Access
A critical vulnerability, identified as CVE-2026-96940, has been discovered in Microsoft Exchange Server. This flaw allows authenticated attackers to escalate privileges and access other users' mailboxes within the same organization. The vulnerability, rated CVSS 8.8 and classified as "Exploitation More Likely" by Microsoft, primarily affects on-premises Exchange deployments. Although there is currently no evidence of exploitation in the wild, Microsoft has released an out-of-band security update to address the issue.
The vulnerability stems from a weakness in the authorization logic of Microsoft Exchange Server. An authenticated user can exploit this flaw to read emails and attachments from other mailboxes, bypassing standard Role-Based Access Control (RBAC) and Active Directory permissions. The attacker must possess valid credentials for any mailbox in the target organization. The flaw does not enable cross-tenant access, unauthenticated remote code execution, or write/delete/admin control over mailboxes.
Affected products include Microsoft Exchange Server Subscription Edition RTM, Microsoft Exchange Server 2019 Cumulative Update 15 (CU15), Microsoft Exchange Server 2019 Cumulative Update 14 (CU14), and Microsoft Exchange Server 2016 Cumulative Update 23 (CU23). Exchange Online (Microsoft 365) is not affected, as a service-side fix has already been deployed. Organizations are advised to apply the security update and review access logs for any anomalous activity.
As of the time of writing, there is no confirmed exploitation of CVE-2026-96940 in the wild. However, Microsoft rates this vulnerability as "Exploitation More Likely," indicating that public proof-of-concept exploits and active attacks may emerge soon after the patch release. The vulnerability follows recent reports of the China-linked Warlock APT group exploiting Microsoft SharePoint vulnerabilities for ransomware deployment.