Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
- ID
- 31986
- Status
- summarized
- Published
- 06 Oct 2026, 12:21 AM
- Fetched
- 06 Oct 2026, 2:50 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/10/microsoft-exchange-flaw-lets.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.0
- Created
- 06 Oct 2026, 2:51 AM
- Tags
- Audience
- developerssaas_startup_founders
What happened
Microsoft released out-of-band updates for CVE-2026-96940, a CVSS 8.8 weak-authorization flaw in Exchange Server that lets an authenticated attacker escalate privileges and read other users' mailboxes and attachments within the same organization, though not cross-tenant. Affected on-prem builds include Exchange Server Subscription Edition RTM, 2016 Cumulative Update 23, and 2019 Cumulative Update 14 and 15; Exchange Online has a service-side fix and customers need no action. Microsoft tagged exploitability as 'Exploitation More Likely' and credited Jan Mitchell with reporting, but says there is no evidence of in-the-wild exploitation.
Why it matters
If your organization runs any listed on-prem Exchange build, apply the out-of-band update now because Microsoft rates exploitation as 'Exploitation More Likely' and an authenticated user in the same org could read other mailboxes. If you are only on Exchange Online, Microsoft says the service-side fix is already deployed and no action is required, so app developers using Microsoft 365 mail APIs do not need to change code.
Discussion angle
Ask who in the group still runs on-prem Exchange or has clients on the listed builds, and whether a same-org mailbox read plus 'Exploitation More Likely' changes their patch priority versus relying on Exchange Online's automatic fix.