> CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely
[AUTHOR: Pierluigi Paganini]
[DATE: 06/10/2026 14:09]
[LANGUAGE: EN]
Microsoft released emergency updates for Exchange Server to fix CVE-2026-96940, a high-severity flaw that can let attackers gain higher privileges.
Microsoft has released out-of-band security updates for Exchange Server to fix a high-severity vulnerability tracked as CVE-2026-96940 (CVSS score of 8.8). The flaw is caused by weak authorization and can allow an authenticated attacker to gain higher privileges over a network.
Microsoft disclosed the issue on October 2, 2026, and urged customers to install the security updates. Exploitation requires authentication, but successful attacks could give attackers additional access to Exchange systems.
“An authenticated attacker who successfully exploited this vulnerability could gain unauthorized access to other users’ mailboxes within the same organization and read email messages and attachments.” reads the advisory. “The vulnerability does not allow access across tenant boundaries.”
Microsoft researchers Jan Mitchell discovered the vulnerability.
Users running affected on-premises Microsoft Exchange Server versions should install the available security updates to stay protected. Below are the impacted versions:
Microsoft Exchange Server Subscription Edition RTM
Microsoft Exchange Server 2016 Cumulative Update 23
Microsoft Exchange Server 2019 Cumulative Update 15
Microsoft Exchange Server 2019 Cumulative Update 14
Microsoft has already fixed the issue in Exchange Online, so cloud customers don’t need to do anything. Customers running affected on-premises Exchange Server versions should install the relevant security updates listed by Microsoft.
It is interesting to highlight that the IT giant considers the “exploitation more likely.”
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
Pierluigi Paganini
(SecurityAffairs – hacking, Microsoft Exchange Server flaw)