CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely

CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely

CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely

CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely

CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely

Pierluigi Paganini
October 06, 2026

Microsoft released emergency updates for Exchange Server to fix CVE-2026-96940, a high-severity flaw that can let attackers gain higher privileges.

Microsoft has released out-of-band security updates for Exchange Server to fix a high-severity vulnerability tracked as CVE-2026-96940 (CVSS score of 8.8). The flaw is caused by weak authorization and can allow an authenticated attacker to gain higher privileges over a network.

Microsoft disclosed the issue on October 2, 2026, and urged customers to install the security updates. Exploitation requires authentication, but successful attacks could give attackers additional access to Exchange systems.

“An authenticated attacker who successfully exploited this vulnerability could gain unauthorized access to other users’ mailboxes within the same organization and read email messages and attachments.” reads the advisory. “The vulnerability does not allow access across tenant boundaries.”

Microsoft researchers Jan Mitchell discovered the vulnerability.

Users running affected on-premises Microsoft Exchange Server versions should install the available security updates to stay protected. Below are the impacted versions:

  • Microsoft Exchange Server Subscription Edition RTM
  • Microsoft Exchange Server 2016 Cumulative Update 23
  • Microsoft Exchange Server 2019 Cumulative Update 15
  • Microsoft Exchange Server 2019 Cumulative Update 14

Microsoft has already fixed the issue in Exchange Online, so cloud customers don’t need to do anything. Customers running affected on-premises Exchange Server versions should install the relevant security updates listed by Microsoft.

It is interesting to highlight that the IT giant considers the “exploitation more likely.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Microsoft Exchange Server flaw)



About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.