preloader

· · digital-security cve microsoft exchange email-security email-deliverability patch-management europe

Microsoft Exchange Flaw CVE-2026-96940 Lets Insiders Read Other Users’ Mailboxes, and On-Premises Shops Need Out-of-Band Updates

Source: The Hacker News

Microsoft has released out-of-band security updates for a high-severity flaw in Exchange Server that every organization still running on-premises email should treat as this week’s priority. The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scale, and Microsoft describes it as weak authorization that allows an authenticated attacker to elevate privileges over a network.

What the flaw actually exposes

An authenticated attacker can exploit the flaw to gain unauthorized access to other users’ mailboxes within the same organization, and read email messages and attachments. The vulnerability does not allow cross-tenant access, which limits the blast radius for multi-tenant hosting setups, but inside a single organization the impact is serious: one compromised or malicious account can turn a mailbox server into a full intelligence source on your business. Microsoft credits its own researcher Jan Mitchell with the discovery, and while there is no evidence the flaw has been exploited in the wild, Microsoft has tagged it with an Exploitability assessment of Exploitation More Likely, which is the company’s way of saying do not wait for the next Patch Tuesday.

Who needs to act

Exchange Online customers do not need to do anything, because Microsoft has already deployed a related service-side fix to its hosted platform. The updates matter for on-premises deployments of Exchange Server Subscription Edition RTM, Exchange Server 2019 Cumulative Updates 14 and 15, and Exchange Server 2016 Cumulative Update 23, the latter being well past its mainstream support life and a red flag in its own right. Any European organization still holding Exchange 2016 in production should treat this disclosure as a prompt to finish its migration plan, because out-of-band fixes for a 2016 product line are a signal that the legacy window is closing fast.

The wider email security context

The disclosure lands days after Symantec warned that the China-linked Warlock actor is exploiting multiple SharePoint vulnerabilities to deploy its namesake ransomware, with victims concentrated in Portuguese- and Spanish-speaking countries. For European operators, mailboxes remain the crown-jewel target in most intrusion chains, whether the goal is extortion, fraud or onward phishing. Reading other users’ mailboxes quietly is exactly the kind of access that lets an attacker plan business email compromise campaigns while looking like an ordinary employee session.

If your organization runs Exchange on premises and wants a clear plan for patching, hardening and eventually migrating to a supported platform, contact Excello Digital at https://excello.digital/contact/. We help European businesses secure their email infrastructure, tighten mailbox access controls, and keep deliverability and compliance intact while the underlying platform evolves.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!