Skip to content
feed: live
0dayNews
microsoft
● Breaking

Exchange Server OOB Patch Closes Mailbox-Read Flaw

CVE-2026-96940, a CVSS 8.8 privilege escalation flaw in on-prem Microsoft Exchange, lets authenticated attackers read other users' mailboxes. Patch available now; Exchange Online already fixed.

Exchange Server OOB Patch Closes Mailbox-Read Flaw
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgapMorgan "airgap" Reyes·Published ·1 min read

Patch released out-of-band. On-premises Exchange admins: apply it now.

CVE-2026-96940 is a privilege escalation flaw in Microsoft Exchange Server, CVSS 8.8 (high). An authenticated user within an Exchange organization can escalate privileges and read other users’ mailboxes, including email content and attachments. Cross-tenant access: not possible. Scope is limited to the attacker’s own organization.

Affected builds: Exchange Server Subscription Edition RTM, Exchange 2016 CU23, Exchange 2019 CU14, Exchange 2019 CU15.

Exploitation in the wild: not observed as of publication. Microsoft’s classification: “Exploitation More Likely.” Still running the vulnerable build after this weekend. That is a choice, not bad luck.

Exchange Online is already patched server-side, automatically. No customer action required there.

On-premises Exchange is not automatically patched. Install the security update immediately via standard Microsoft Update channels.

Disclosed October 2, 2026. Credit: researcher Jan Mitchell. Full advisory at Microsoft MSRC; detailed writeup at The Hacker News.

This is a separate issue from the Void Blizzard OWA zero-day campaign reported earlier this year. Organizations running Exchange 2016 or 2019 should also note: Extended Security Update support ends this month, making this one of the last formal patches those versions will receive. Microsoft also issued an out-of-band Windows RDS and Hyper-V fix in September, a reminder that OOB releases are not unusual when exploitation risk is rated high.

Related CVEs
  • [ HIGH ]CVE-2026-96940Microsoft Exchange Server privilege escalation via weak authorization

Found this useful? Share it.