Microsoft patched CVE-2026-96940, a high-severity flaw rated 8.8 in Exchange Server that lets an authenticated attacker gain unauthorized access to other users' mailboxes within the same organization. The weakness stems from weak authorization controls that permit privilege escalation, exposing colleagues' messages and attachments. Affected builds include Exchange Server Subscription Edition RTM, Exchange Server 2016 Cumulative Update 23, and Exchange Server 2019 Cumulative Updates 14 and 15. Microsoft already applied a related service-side fix to Exchange Online, so on-premises administrators must install the updates themselves. There is no evidence of active exploitation, but Microsoft rated the flaw Exploitation More Likely.