Microsoft Fixes Exchange Flaw That Could Let Attackers Read Other Users’ Mailboxes

Microsoft has released security updates for a high-severity Exchange Server vulnerability that could allow an authenticated attacker to access other users’ mailboxes and read their emails and attachments.

The flaw, tracked as CVE-2026-96940, carries a CVSS severity score of 8.8. An attacker would already need valid access to the affected Exchange organization, but successful exploitation could let that account reach mailboxes it would not normally be authorized to view.

Microsoft says the issue does not allow access across organizational boundaries and that it has not observed active exploitation but rates exploitation as more likely.

The fix was added on October 2 in a revised version of Microsoft’s September Exchange Server security updates. Microsoft said the vulnerability was discovered internally.

On-Premises Exchange Servers Need the Update

Affected versions include Exchange Server Subscription Edition RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23.

Exchange Online customers don’t need to take action because Microsoft has already deployed a related server-side fix to its cloud service. Administrators running affected on-premises Exchange servers should install the revised security updates.

The authentication requirement limits the flaw compared with vulnerabilities that can be exploited remotely without credentials, but it could still be useful to an attacker who has already compromised a legitimate account. Microsoft recommends applying the update as soon as possible and using its Exchange Server Health Checker afterward to confirm that the installation completed successfully.