CVE-2026-96940 (CVSS 8.8) lets any authenticated user of an on-premises Exchange server read other people’s mail and attachments in the same organisation. Microsoft shipped an out-of-band update on 2 October; Exchange Online is already fixed.
What is at stake
On 2 October 2026 Microsoft released an out-of-band security update for Exchange Server. The flaw, CVE-2026-96940 (CVSS 8.8), is a weak authorisation check: an attacker who holds any valid account in the organisation can open other users’ mailboxes and read their messages and attachments. It does not cross from one tenant to another.
Microsoft has not seen it exploited yet, but rates exploitation as “more likely”. The condition is easy to meet: one phished employee, or one password stolen by malware on a home computer — exactly the scenario behind this summer’s French tax-office breach — and the attacker can read the finance director’s or the CEO’s mail.
Who is affected
- Exchange Online (Microsoft 365): nothing to do, Microsoft has already fixed the service.
- On-premises Exchange, including hybrid deployments: update to at least build 15.01.2507.075 (Exchange 2016 CU23), 15.02.1544.048 (Exchange 2019 CU14), 15.02.1748.053 (Exchange 2019 CU15) or 15.02.2562.053 (Subscription Edition RTM).
What to do now
- Check the exact build of each Exchange server from the Exchange Management Shell with
Get-Command Exsetup.exe | ForEach-Object { $_.FileVersionInfo }— the version shown in the admin console does not always include security updates. - Install the update on every server, starting with those that publish Outlook on the web or ActiveSync on the internet.
- Look at mailbox access: enable or review mailbox audit logging and look for accounts that opened mailboxes other than their own without delegation.
- Protect the accounts themselves: multi-factor authentication on Outlook on the web and remote access, and a password reset for any account suspected of compromise.
Our take
Exchange 2016 and 2019 left mainstream support in October 2025. If you still run them, every new flaw is a reminder to plan the move to Exchange Subscription Edition or to Exchange Online — on-premises mail servers are among the most targeted systems in a company.
Sources
- Microsoft — Security Update Guide, CVE-2026-96940
- CERT-FR — CERTFR-2026-AVI-1258
- The Hacker News — Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users’ Mailboxes
Worried your servers are exposed? Our team audits, patches and monitors Linux and cloud infrastructure 24/7.
Talk to an expert