Microsoft Issues Emergency Exchange Fix for Flaw That Exposes Colleagues' Mailboxes
Microsoft has released out-of-band security updates for a high-severity vulnerability in Microsoft Exchange Server, tracked as CVE-2026-96940 and rated 8.8 on the CVSS scale. In an advisory dated October 2, 2026, Microsoft described the problem as weak authorisation that lets an authenticated attacker elevate privileges over a network.
In practical terms, an attacker who already has a valid login could gain unauthorised access to other users' mailboxes in the same organisation and read email messages and attachments. Microsoft says the flaw does not allow access across different tenants. Exchange Online has already received a related service-side fix, so its customers do not need to act. Organisations running affected on-premises Exchange Server products are advised to install the updates. The source article lists the impacted versions, but that list is not included in the excerpt reviewed here.
The flaw was reported by Microsoft researcher Jan Mitchell. There is no evidence it has been exploited in the wild, but Microsoft has rated it "Exploitation More Likely", so prompt patching is important. The disclosure follows a Symantec warning that the China-linked Warlock actor is exploiting multiple Microsoft SharePoint vulnerabilities to deploy ransomware against organisations in Portuguese- and Spanish-speaking countries.