Exchange Flaw CVE-2026-96940 Exposes Users’ Mailboxes

Microsoft found the weak-authorization bug itself and fixed Exchange Online server-side, but on-premises Exchange servers need the new V2 update.

By Vivek • • 4 Min Read • 0 • Follow on Google News Add to Preferred Source
Microsoft Exchange mailbox access vulnerability

Microsoft has pushed out-of-band security updates for Exchange Server to fix a flaw that lets an authenticated attacker open other users’ mailboxes in the same organisation and read their emails and attachments.

The vulnerability, tracked as CVE-2026-96940, has a CVSS score of 8.8. Microsoft describes it as weak authorisation in Exchange Server that lets an authenticated attacker elevate privileges over a network, and published its advisory on October 2, 2026. It affects Exchange Server Subscription Edition (SE) RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23.

The fix arrives with the V2 release of the September 2026 Exchange security updates. Microsoft said the addition of CVE-2026-96940 is the only difference from the original September release, and the Exchange Team said it shipped the update earlier than planned and urged administrators to install it quickly.

How does CVE-2026-96940 work?

Authentication is how Exchange checks who a user is. Authorisation determines what the user may open. CVE-2026-96940 is a failure of the second check. An attacker who can already sign in can reach other users’ mailboxes in the same organisation and read messages and attachments, but cannot cross into another tenant.

The CVE record’s scoring shows how little the attacker needs. The vector rates the flaw as network-reachable, low-complexity, requiring only low privileges and no user interaction, with high impact on confidentiality, integrity, and availability. In practice, one ordinary mailbox account is enough, so stolen credentials for any single employee would meet the bar.

Microsoft has not said which Exchange component contains the flaw. Its announcement pointed customers to the Security Update Guide and the KB articles for CVE-specific detail. No public proof-of-concept exploit is listed, and the flaw is not in CISA’s Known Exploited Vulnerabilities catalog. It is also unrelated to CVE-2026-62911, an earlier Exchange flaw that does have a public proof of concept for an authentication relay attack.

“We identified the vulnerability internally and are not aware of active exploitation,” the Exchange Team said. The Hacker News reports that Microsoft credited its own researcher, Jan Mitchell, with finding the bug and rated it “Exploitation More Likely.” The CVE carries an “Important” severity rating.

Which Exchange versions need the update?

Exchange Server SE RTM is fixed by KB5129955, which brings servers to build 15.02.2562.053. Exchange Server 2019 CU15 is fixed by KB5129956 (build 15.02.1748.053), Exchange Server 2019 CU14 by KB5129957 (build 15.02.1544.048), and Exchange Server 2016 CU23 by KB5129958 (build 15.01.2507.075). Any server below those builds on the matching branch is vulnerable.

Microsoft has already applied a service-side fix to Exchange Online, so cloud-only customers do not need to take any action.

Exchange 2016 and 2019 are past the end of support. Only organisations enrolled in the Period 2 Extended Security Update program can get the 2016 and 2019 updates released between May and October 2026. Microsoft advises organisations outside the program to move to Exchange Server SE to keep receiving security fixes.

Organisations that installed the original September update are not covered. That release, which shipped on September 8, closed nine Exchange vulnerabilities, but admins who applied it need to deploy the V2 packages and should not assume their servers already have the new fix. According to Franky’s Web, the SE package (KB5129955) appeared on Windows Update on October 1, before Microsoft had published release notes or a blog announcement.

What should Exchange administrators do?

Microsoft says the update must be applied to every Exchange server, including those used only for management, and to every workstation running the Exchange Management Tools. Hybrid organisations must patch their on-premises infrastructure as well, including servers dedicated solely to recipient management.

Microsoft recommends taking inventory first with the Exchange Server Health Checker script, which flags unsupported cumulative updates and missing security updates. Because Exchange security updates are cumulative, servers on a supported CU can install the V2 package directly without applying earlier updates first. After installation, admins should reboot and confirm that all Exchange services have started.

Disabled services after installation can mean the update did not finish, and Microsoft’s SetupAssist script is the recommended recovery path. Hybrid deployments that change their authentication certificate after patching should rerun the Hybrid Configuration Wizard.

The V2 release has two known issues that Microsoft says it will fix in future updates. Calendar apps requesting published calendars in ICS format can encounter HTTP 500 errors, and ContentEngine deadlocks can occur on servers processing Korean-language email due to missing WordBreaker rule files. The release also fixes wrapper messages appearing in shared mailbox inboxes in hybrid environments and free/busy lookups failing for delegated mailboxes in hybrid setups that use only the Microsoft Graph API.

Community Discussion

Join the conversation. Ask questions, share solutions, and help others.

0 Comments

Be the first to start the discussion!

Leave a Comment

Your email address will not be published. Required fields are marked *

We respect your privacy, your information is safe with us.

Latest Articles

View all