Threat Intelligence

Microsoft Issues Emergency Exchange Fix for Flaw That Exposes Colleagues' Mailboxes

The Hacker News · 6 Oct 2026
Key Takeaway If your business runs Exchange Server on its own premises, check your version against Microsoft's advisory and apply the update promptly, rather than waiting for signs of attack.

Microsoft has released out-of-band security updates for a high-severity vulnerability in Microsoft Exchange Server, tracked as CVE-2026-96940 and rated 8.8 on the CVSS scale. In an advisory dated October 2, 2026, Microsoft described the problem as weak authorisation that lets an authenticated attacker elevate privileges over a network.

In practical terms, an attacker who already has a valid login could gain unauthorised access to other users' mailboxes in the same organisation and read email messages and attachments. Microsoft says the flaw does not allow access across different tenants. Exchange Online has already received a related service-side fix, so its customers do not need to act. Organisations running affected on-premises Exchange Server products are advised to install the updates. The source article lists the impacted versions, but that list is not included in the excerpt reviewed here.

The flaw was reported by Microsoft researcher Jan Mitchell. There is no evidence it has been exploited in the wild, but Microsoft has rated it "Exploitation More Likely", so prompt patching is important. The disclosure follows a Symantec warning that the China-linked Warlock actor is exploiting multiple Microsoft SharePoint vulnerabilities to deploy ransomware against organisations in Portuguese- and Spanish-speaking countries.

Microsoft Exchange Vulnerability Patch Management CVE-2026-96940

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.