Microsoft fixes critical Exchange flaw allowing mailbox access attacks
Microsoft has issued an urgent fix for a high-severity flaw in its Exchange Server, identified as CVE-2026-96940. This vulnerability allows attackers with compromised user credentials to escalate privileges and access other employees’ mailboxes within the same organization. The flaw, rated 8.8 out of 10 on the severity scale, could enable threat actors to read confidential emails and attachments, potentially leading to follow-up attacks such as Business Email Compromise (BEC).
The bug cannot be exploited for cross-tenant access, but attackers can still gain unauthorized entry by obtaining credentials through methods like phishing or purchasing them on the dark web. Microsoft labeled the vulnerability as "exploitation more likely," urging users to apply the patch immediately. While no active exploitation has been reported, the risk remains significant, particularly for organizations using on-premises Exchange Server products.
Users of Exchange Online are already protected, as Microsoft deployed a service-side fix. However, those using on-prem Exchange Server versions, including Microsoft Exchange Server Subscription Edition RTM, Exchange Server 2016 Cumulative Update 23, and Exchange Server 2019 Cumulative Updates 14 and 15, must upgrade to the latest version to avoid exposure. The patch was released ahead of its intended schedule, emphasizing the urgency of the threat.
Microsoft also noted that Exchange Server 2016 and 2019 reached their end-of-support last year. Security updates are only available to organizations enrolled in the Period 2 Extended Security Update (ESU) program, which provides access to security fixes until October 2026. Administrators are advised to run Microsoft’s Exchange Server Health Checker after installing the update to ensure proper deployment.