DKDKCISSPSearch
Policy

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes

Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions.

DKCISSP News DeskThe Hacker News5 Oct 2026, 9:51 pm
Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions.

The vulnerability, tracked as CVE-2026-96940 , is rated 8.8 on the CVSS scoring system.

Microsoft said in an advisory released on October 2, 2026.

The following versions are impacted - Redmond has credited Microsoft researcher Jan Mitchell with discovering and reporting the flaw.

The disclosure comes days after Broadcom-owned Symantec warned that the China-linked Warlock actor is exploiting multiple vulnerabilities in Microsoft SharePoint to deploy its namesake ransomware in attacks targeting organizations in Portuguese- and Spanish-speaking countries.

The Windows maker said an authenticated attacker can exploit this flaw to gain unauthorized access to other users' mailboxes within the same organization and read email messages and attachments.

As a result, Exchange Online customers are not required to take any action.

Users of affected on-premises Microsoft Exchange Server products are advised to install the updates to stay protected.

Although there is no evidence of the flaw being weaponized in the wild, Microsoft has tagged it with an Exploitability assessment of making it essential that users move quickly to apply the fixes.

Microsoft has already deployed a to Exchange Online to address the issue.

What happened

Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions.

The vulnerability, tracked as CVE-2026-96940 , is rated 8.8 on the CVSS scoring system.

Microsoft said in an advisory released on October 2, 2026.

What changed

The following versions are impacted - Redmond has credited Microsoft researcher Jan Mitchell with discovering and reporting the flaw.

The disclosure comes days after Broadcom-owned Symantec warned that the China-linked Warlock actor is exploiting multiple vulnerabilities in Microsoft SharePoint to deploy its namesake ransomware in attacks targeting organizations in Portuguese- and Spanish-speaking countries.

Who is affected

The Windows maker said an authenticated attacker can exploit this flaw to gain unauthorized access to other users' mailboxes within the same organization and read email messages and attachments.

As a result, Exchange Online customers are not required to take any action.

Why it matters

Users of affected on-premises Microsoft Exchange Server products are advised to install the updates to stay protected.

Technical details

Although there is no evidence of the flaw being weaponized in the wild, Microsoft has tagged it with an Exploitability assessment of making it essential that users move quickly to apply the fixes.

Response

Microsoft has already deployed a to Exchange Online to address the issue.

Attribution

The Hacker News: Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions.

What to watch next

Watch for additional victim details, indicators of compromise and follow-on exploitation reports.

Watch for revised vendor guidance, fixed versions and mitigation updates.

MORE IN POLICY

More cybersecurity reporting

More UK Schools Are Recovering Faster from Cyber IncidentsInfosecurity Magazine · 5 Oct 2026, 3:00 pmCritical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host FilesThe Hacker News · 17 Sept 2026, 9:07 pmCritical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS ZoneThe Hacker News · 17 Sept 2026, 6:00 pmNIS Directive has Positive Effect, though Study Finds Gaps in Cybersecurity Investment Exist | ENISAENISA · 27 Aug 2026, 7:10 pm