Microsoft Patches High-Severity Exchange Server Flaw Allowing Mailbox Access
Microsoft has issued urgent out-of-band security updates to fix a high-severity flaw in its Exchange Server. The vulnerability, identified as CVE-2026-96940, has a CVSS score of 8.8 and could allow authenticated attackers to escalate privileges and access other users' mailboxes within the same organization.
According to Microsoft's advisory released on October 2, 2026, the flaw stems from weak authorization in Exchange Server. An attacker could exploit this to read emails and attachments but cannot gain cross-tenant access. The company has already applied a service-side fix to Exchange Online, meaning those customers do not need to take further action.
On-premises Exchange Server users, however, must install the latest updates to protect their systems. The affected versions include Microsoft Exchange Server Subscription Edition RTM, Exchange Server 2016 Cumulative Update 23, and Exchange Server 2019 Cumulative Updates 14 and 15.
The flaw was discovered by Microsoft researcher Jan Mitchell, and while there is no evidence of active exploitation, Microsoft has rated the likelihood of exploitation as 'More Likely.' This warning comes shortly after Symantec reported that the China-linked Warlock actor is exploiting SharePoint vulnerabilities to deploy ransomware.