Microsoft has shipped an out-of-band fix for CVE-2026-96940, an Exchange Server flaw scored 8.8. A user who already has a mailbox account can read other people's mail and attachments inside the same organization.
What happened
Microsoft calls it weak authorization. The attacker must already be authenticated. The bug does not cross tenant boundaries, and Microsoft says it has not seen active exploitation. It still rates exploitation as more likely, and this class of mailbox bug has been abused before.
The fix landed in the September 2026 V2 security update, which Microsoft said was published ahead of schedule. The original September update does not cover this issue. Microsoft's 6 October early-update note lists this as the one CVE in that release.
Who is affected
Exchange Online already has a service-side fix. Customers who only use Exchange Online do not need to patch for this bug.
- Exchange Server Subscription Edition RTM
- Exchange Server 2019 CU14 and CU15, if the organization is in the Period 2 extended support program
- Exchange Server 2016 CU23, on the same extended-support terms
Install the update on every Exchange server and on workstations that run the Exchange management tools.
What to do now
Install the September 2026 V2 security update on every on-prem Exchange server, not the original September package. Confirm Exchange Online tenants need no action for this CVE, then review mailbox-access logs for unusual reads by ordinary accounts.
Source: The Hacker News, citing Microsoft's advisory.
Also on the blog
- ClickFix cache smuggling bypasses the Windows Run character limit
- HPE iLO 7 CVE-2026-79820 scores 9.0 on user validation
- Cling botnet hides operator commands inside STUN traffic
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.