Microsoft issues urgent security updates for CVE-2026-96940 flaw in Exchange Server allowing mailbox access

Published:

Microsoft has issued urgent out-of-band security updates to address a critical vulnerability in Microsoft Exchange Server, identified as CVE-2026-96940, which has been rated 8.8 on the CVSS scoring system. This flaw allows authenticated attackers to escalate privileges and gain unauthorized access to other users’ mailboxes within the same organization, potentially allowing them to read email messages and attachments.

According to Microsoft’s advisory released on October 2, 2026, the vulnerability stems from weak authorization mechanisms in Exchange Server. While it does not permit cross-tenant access, the risk it poses to organizational email security is significant. Microsoft has already implemented a related service-side fix for Exchange Online, meaning that users of this service do not need to take any action. However, on-premises users must install the updates to mitigate the risk.

Affected Versions and Recommendations

The following versions of Microsoft Exchange Server are impacted by this vulnerability:

  • Microsoft Exchange Server Subscription Edition RTM
  • Microsoft Exchange Server 2016 Cumulative Update 23
  • Microsoft Exchange Server 2019 Cumulative Update 15
  • Microsoft Exchange Server 2019 Cumulative Update 14

Microsoft has credited researcher Jan Mitchell for discovering and reporting the flaw. Although there is currently no evidence that the vulnerability has been exploited in the wild, Microsoft has assessed its exploitability as “Exploitation More Likely,” urging users to apply the fixes promptly to safeguard their systems.

Context of the Disclosure

This disclosure follows a warning from Broadcom-owned Symantec regarding the China-linked Warlock actor, which is reportedly exploiting multiple vulnerabilities in Microsoft SharePoint to deploy ransomware in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The timing of these alerts underscores the heightened threat landscape surrounding Microsoft products, making it imperative for organizations to remain vigilant and proactive in their cybersecurity measures.

As organizations continue to rely heavily on email communication, addressing vulnerabilities like CVE-2026-96940 is crucial for maintaining the integrity and confidentiality of sensitive information. Cybersecurity professionals and IT leaders are advised to prioritize the installation of these updates to mitigate potential risks.

For further details, refer to the advisory from The Hacker News.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Astroscale U.S. plans 2026 launch of Provisioner® spacecraft to demonstrate on-orbit refueling for missile defense systems

Astroscale U.S. is set to launch its Provisioner® spacecraft in 2026, aiming to demonstrate on-orbit refueling capabilities that could significantly enhance missile defense systems....

Authorities arrest three alleged members of KillSec ransomware group in global operation

Authorities have arrested three alleged members of the KillSec ransomware group, including its suspected leader, a 16-year-old, as part of a coordinated global operation...

French Navy conducts first at-sea tests of Rampart CIWS during WILDFIRE 26.2 exercise

The French Navy has successfully conducted its first at-sea tests of the Rampart multi-purpose modular launching system, developed by Naval Group, during the WILDFIRE...

AI’s evolving role in cyber threats and defenses highlighted in Microsoft’s 2026 Digital Defense Report

The 2026 Microsoft Digital Defense Report reveals a significant evolution in the role of artificial intelligence (AI) within the cybersecurity landscape, highlighting how threat...