Microsoft has issued urgent out-of-band security updates to address a critical vulnerability in Microsoft Exchange Server, identified as CVE-2026-96940, which has been rated 8.8 on the CVSS scoring system. This flaw allows authenticated attackers to escalate privileges and gain unauthorized access to other users’ mailboxes within the same organization, potentially allowing them to read email messages and attachments.
According to Microsoft’s advisory released on October 2, 2026, the vulnerability stems from weak authorization mechanisms in Exchange Server. While it does not permit cross-tenant access, the risk it poses to organizational email security is significant. Microsoft has already implemented a related service-side fix for Exchange Online, meaning that users of this service do not need to take any action. However, on-premises users must install the updates to mitigate the risk.
Affected Versions and Recommendations
The following versions of Microsoft Exchange Server are impacted by this vulnerability:
- Microsoft Exchange Server Subscription Edition RTM
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Update 15
- Microsoft Exchange Server 2019 Cumulative Update 14
Microsoft has credited researcher Jan Mitchell for discovering and reporting the flaw. Although there is currently no evidence that the vulnerability has been exploited in the wild, Microsoft has assessed its exploitability as “Exploitation More Likely,” urging users to apply the fixes promptly to safeguard their systems.
Context of the Disclosure
This disclosure follows a warning from Broadcom-owned Symantec regarding the China-linked Warlock actor, which is reportedly exploiting multiple vulnerabilities in Microsoft SharePoint to deploy ransomware in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The timing of these alerts underscores the heightened threat landscape surrounding Microsoft products, making it imperative for organizations to remain vigilant and proactive in their cybersecurity measures.
As organizations continue to rely heavily on email communication, addressing vulnerabilities like CVE-2026-96940 is crucial for maintaining the integrity and confidentiality of sensitive information. Cybersecurity professionals and IT leaders are advised to prioritize the installation of these updates to mitigate potential risks.
For further details, refer to the advisory from The Hacker News.


