Source: The Hacker News
Microsoft has released out-of-band security updates for a high-severity flaw in Exchange Server that every organization still running on-premises email should treat as this week’s priority. The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scale, and Microsoft describes it as weak authorization that allows an authenticated attacker to elevate privileges over a network.
What the flaw actually exposes
An authenticated attacker can exploit the flaw to gain unauthorized access to other users’ mailboxes within the same organization, and read email messages and attachments. The vulnerability does not allow cross-tenant access, which limits the blast radius for multi-tenant hosting setups, but inside a single organization the impact is serious: one compromised or malicious account can turn a mailbox server into a full intelligence source on your business. Microsoft credits its own researcher Jan Mitchell with the discovery, and while there is no evidence the flaw has been exploited in the wild, Microsoft has tagged it with an Exploitability assessment of Exploitation More Likely, which is the company’s way of saying do not wait for the next Patch Tuesday.
Who needs to act
Exchange Online customers do not need to do anything, because Microsoft has already deployed a related service-side fix to its hosted platform. The updates matter for on-premises deployments of Exchange Server Subscription Edition RTM, Exchange Server 2019 Cumulative Updates 14 and 15, and Exchange Server 2016 Cumulative Update 23, the latter being well past its mainstream support life and a red flag in its own right. Any European organization still holding Exchange 2016 in production should treat this disclosure as a prompt to finish its migration plan, because out-of-band fixes for a 2016 product line are a signal that the legacy window is closing fast.
The wider email security context
The disclosure lands days after Symantec warned that the China-linked Warlock actor is exploiting multiple SharePoint vulnerabilities to deploy its namesake ransomware, with victims concentrated in Portuguese- and Spanish-speaking countries. For European operators, mailboxes remain the crown-jewel target in most intrusion chains, whether the goal is extortion, fraud or onward phishing. Reading other users’ mailboxes quietly is exactly the kind of access that lets an attacker plan business email compromise campaigns while looking like an ordinary employee session.
If your organization runs Exchange on premises and wants a clear plan for patching, hardening and eventually migrating to a supported platform, contact Excello Digital at https://excello.digital/contact/. We help European businesses secure their email infrastructure, tighten mailbox access controls, and keep deliverability and compliance intact while the underlying platform evolves.
