Skip to content
feed: live
0dayNews
CVE Record
[ HIGH ]CVE-2026-96940

Microsoft Exchange Server privilege escalation via weak authorization

An authenticated attacker in the same Exchange org can escalate privileges and read other users' mailboxes and attachments. Affects on-prem Exchange Server; Exchange Online was patched automatically.

Vendor
Microsoft
Product
Exchange Server (SE RTM, 2016 CU23, 2019 CU14, 2019 CU15)
CVSS
8.8
EPSS (exploit probability)
0.5%
Status
patched
Published

CVE-2026-96940 is a weak authorization flaw in Microsoft Exchange Server. An authenticated user within an Exchange organization can escalate privileges and read the mailboxes of other users in the same organization, including email content and attachments. Cross-tenant access is not possible.

Affected versions: Exchange Server Subscription Edition RTM, Exchange 2016 CU23, Exchange 2019 CU14, Exchange 2019 CU15. Exchange Online was patched automatically server-side; no customer action required for cloud deployments.

Microsoft released an out-of-band security update on October 2, 2026. Exploitation in the wild has not been observed, but Microsoft rates this as “Exploitation More Likely.” On-premises administrators should apply the update immediately.

Discovered and reported by researcher Jan Mitchell.