Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users’ Mailboxes

Ravie LakshmananOct 05, 2026Vulnerability / Email Security

Microsoft recently released urgent security updates to fix a critical vulnerability in Microsoft Exchange Server that could potentially allow an attacker to elevate privileges in specific scenarios.

The vulnerability, identified as CVE-2026-96940, has been given a CVSS score of 8.8.

According to Microsoft, the flaw in Microsoft Exchange Server’s authorization mechanism could enable an authenticated attacker to raise their privileges over a network. This could lead to unauthorized access to other users’ mailboxes within the same organization, allowing the attacker to view email messages and attachments. However, the vulnerability does not permit access across different tenants.

Microsoft has already rolled out a fix for Exchange Online to address the issue, so Exchange Online users do not need to take any additional steps. On the other hand, users of affected on-premises Microsoft Exchange Server products are advised to install the updates promptly. The impacted versions include:

  • Microsoft Exchange Server Subscription Edition RTM
  • Microsoft Exchange Server 2016 Cumulative Update 23
  • Microsoft Exchange Server 2019 Cumulative Update 15
  • Microsoft Exchange Server 2019 Cumulative Update 14

The discovery of the vulnerability is credited to Microsoft researcher Jan Mitchell. While there is no evidence of the flaw being exploited in the wild, Microsoft has assessed it as “Exploitation More Likely,” emphasizing the importance of applying the fixes promptly.

This announcement follows a warning from Symantec, owned by Broadcom, about the China-linked Warlock actor exploiting multiple vulnerabilities in Microsoft SharePoint to distribute ransomware, targeting organizations in Portuguese- and Spanish-speaking regions.