DKDKCISSPSearch
Vulnerabilities

Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940) - Help Net Security

Microsoft has pushed out an out-of-band security update for Exchange Server that fixes a high-severity vulnerability (CVE-2026-96940) that may allow authenticated attackers to read emails and attachments of other users in the same organization, but CVE-2026-96940 was discovered internally and, according to the Exchange Server Team, they Nevertheless, Microsoft thinks that the flaw could be consistently exploited and notes that this type of vulnerability has been exploited in the past, so the company advises Exchange Server admins to update sooner rather than later.

DKCISSP News DeskHelp Net Security5 Oct 2026, 4:08 pm
Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940) - Help Net Security
Image courtesy of Help Net Security. Original report
DKCISSP REPORT

Microsoft has pushed out an out-of-band security update for Exchange Server that fixes a high-severity vulnerability (CVE-2026-96940) that may allow authenticated attackers to read emails and attachments of other users in the same organization, but CVE-2026-96940 was discovered internally and, according to the Exchange Server Team, they Nevertheless, Microsoft thinks that the flaw could be consistently exploited and notes that this type of vulnerability has been exploited in the past, so the company advises Exchange Server admins to update sooner rather than later.

Microsoft has deployed a related service-side fix to Exchange Online late last week, taking customers by surprise as the security updates were not immediately accompanied with a KB article explaining their content.

That misstep was soon after acknowledged by Microsoft, when the Exchange Server Team explained that the release sequence of this specific update was a bit strange because it was published ahead of its intended schedule.

(They did not explain why that happened.) The security update is available for on-prem servers running Exchange Server Subscription RTM, Exchange Server 2019 cumulative updates 14 and 15, and Exchange Server 2016 cumulative update 23.

What happened

Microsoft has pushed out an out-of-band security update for Exchange Server that fixes a high-severity vulnerability (CVE-2026-96940) that may allow authenticated attackers to read emails and attachments of other users in the same organization, but CVE-2026-96940 was discovered internally and, according to the Exchange Server Team, they Nevertheless, Microsoft thinks that the flaw could be consistently exploited and notes that this type of vulnerability has been exploited in the past, so the company advises Exchange Server admins to update sooner rather than later.

Microsoft has deployed a related service-side fix to Exchange Online late last week, taking customers by surprise as the security updates were not immediately accompanied with a KB article explaining their content.

That misstep was soon after acknowledged by Microsoft, when the Exchange Server Team explained that the release sequence of this specific update was a bit strange because it was published ahead of its intended schedule.

Who is affected

(They did not explain why that happened.) The security update is available for on-prem servers running Exchange Server Subscription RTM, Exchange Server 2019 cumulative updates 14 and 15, and Exchange Server 2016 cumulative update 23.

Attribution

Help Net Security: Microsoft has pushed out an out-of-band security update for Exchange Server that fixes a high-severity vulnerability (CVE-2026-96940) that may allow authenticated attackers to read emails and attachments of other users in the same organization, but “does not allow access across tenant boundaries.” CVE-2026-96940 was discovered internally and, according to the Exchange Server Team, they “are not aware of active exploitation.” Nevertheless, Microsoft thinks that the flaw could be consistently exploited and notes that this type of vulnerability has been exploited in the past, so the company advises Exchange Server admins to update sooner rather than later.

What to watch next

Watch for additional victim details, indicators of compromise and follow-on exploitation reports.

Watch for revised vendor guidance, fixed versions and mitigation updates.

MORE IN VULNERABILITIES

More cybersecurity reporting

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCEThe Hacker News · 5 Oct 2026, 1:39 pmAttackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOTThe Hacker News · 5 Oct 2026, 1:00 pmCVE-2023-36025 (SmartScreen Bypass) Vulnerability: Analysis & Detection | HuntressHuntress · 4 Oct 2026, 5:30 amFortinet FortiMail bug exploited in the wild, added to CISA KEV listSC Media · 3 Oct 2026, 12:20 am