Microsoft Patches High-Severity Exchange Server Flaw
Microsoft has issued urgent security updates to address a critical flaw in Exchange Server, identified as CVE-2026-96940. This vulnerability, rated with a CVSS score of 8.8, stems from weak authorization and allows authenticated attackers to escalate their privileges within a network.
The flaw was disclosed by Microsoft on October 2, 2026, with a warning that exploitation is more likely. Successful attacks could grant unauthorized access to other users' mailboxes within the same organization, enabling attackers to read emails and attachments. However, the vulnerability does not extend across tenant boundaries.
Microsoft researcher Jan Mitchell discovered the flaw. The affected versions of Exchange Server include Microsoft Exchange Server Subscription Edition RTM, Exchange Server 2016 Cumulative Update 23, and Exchange Server 2019 Cumulative Updates 15 and 14. Cloud customers using Exchange Online are already protected, but on-premises users must install the latest security updates.