Last updated: October 7, 2026 at 2:03 PM UTC
All 903 Vulnerability 367 Breach 144 Threat 385 Defense 7
Tag: on-premises (1 article)Clear

Microsoft Exchange Server flaw lets authenticated users read other mailboxes in the same organization

Microsoft patched CVE-2026-96940, a high-severity flaw rated 8.8 in Exchange Server that lets an authenticated attacker gain unauthorized access to other users' mailboxes within the same organization. The weakness stems from weak authorization controls that permit privilege escalation, exposing colleagues' messages and attachments. Affected builds include Exchange Server Subscription Edition RTM, Exchange Server 2016 Cumulative Update 23, and Exchange Server 2019 Cumulative Updates 14 and 15. Microsoft already applied a related service-side fix to Exchange Online, so on-premises administrators must install the updates themselves. There is no evidence of active exploitation, but Microsoft rated the flaw Exploitation More Likely.

Check
Install the Exchange Server updates on all on-premises Subscription Edition, 2016, and 2019 builds, since the Exchange Online fix does not cover self-hosted servers.
Affected
Unpatched on-premises Exchange Server lets an authenticated user escalate privileges and read other users' mailbox messages and attachments across the same organization.
Fix
Deploy Microsoft's Exchange Server updates, review mailbox access logs for unauthorized cross-user access, and limit accounts on internet-facing Exchange deployments.