Exchange Server CVE-2026-96940: mailbox access flaw patched

Exchange Server CVE-2026-96940: mailbox access flaw patched

At a glance

Severity HIGH
CVSS CVE-2026-96940: 8.8
EPSS (30-day exploit probability) CVE-2026-96940: 0.5%
In CISA KEV (exploited) No
Vendor Microsoft
CVE IDs CVE-2026-96940

Microsoft has released an out-of-band security update for on-premises Exchange Server that fixes CVE-2026-96940, a high-severity Exchange Server vulnerability with a CVSS score of 8.8. According to Help Net Security, an authenticated attacker could read the emails and attachments of other users in the same organization. Microsoft says it is not aware of active exploitation, and the CVE is not in CISA’s Known Exploited Vulnerabilities (KEV) catalog at the time of writing.

What happened

The flaw was discovered internally by Microsoft, according to the Exchange Server Team as quoted by Help Net Security. The update was published ahead of its intended schedule. A related service-side fix reached Exchange Online late last week, before a KB article explained it, which surprised customers. Microsoft later acknowledged the odd release sequence but, per the report, did not say why it happened.

Microsoft reportedly says the issue “does not allow access across tenant boundaries”, so the exposure is inside a single organization.

Am I affected? Exchange Server versions

The update is available for these on-premises releases, per the source report:

  • Exchange Server Subscription Edition RTM
  • Exchange Server 2019 cumulative updates 14 and 15
  • Exchange Server 2016 cumulative update 23

The NVD entry does not list affected versions yet (not disclosed in the NVD record). Exchange Online received a service-side fix, so cloud-only tenants do not need to install anything themselves.

Technical details of CVE-2026-96940

  • Weakness: NVD describes weak authorization in Exchange Server (CWE-1390, weak authentication) that lets an authenticated attacker elevate privileges over a network.
  • CVSS 3.1: 8.8 High, vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. That means network reachable, low complexity, low privileges, no user interaction.
  • Exploitation: Microsoft is not aware of active exploitation. Not listed in CISA KEV.
  • EPSS: 0.00496, meaning a low modelled probability of exploitation in the next 30 days.
  • Description mismatch: NVD frames the issue as privilege elevation, while the news report describes it as cross-user mailbox reading. The sources do not reconcile the two, so treat the exact impact as not fully specified.

Why this matters

Analysis, not new facts. The attack needs a valid account, so the realistic threat is a phished or compromised mailbox user, or a malicious insider, using it to reach executive or finance mail. Microsoft notes that this type of vulnerability has been exploited in the past and calls the flaw consistently exploitable, so a low EPSS today should not delay patching for long. Mailbox content is a prime target for business email compromise and data theft.

How to detect abuse

No indicators of compromise have been published. These hunting ideas follow from the facts:

  • Review mailbox audit logs for users opening or exporting mailboxes that are not their own.
  • Look for ordinary accounts suddenly making bulk mail or attachment access requests.
  • Check Exchange and IIS logs for unusual authenticated requests from low-privilege accounts.

What to do: fix CVE-2026-96940

  1. Identify every on-premises Exchange server and confirm it runs a supported cumulative update listed above.
  2. Apply the September 2026 v2 security update at the earliest opportunity. Because it is not in KEV, a normal accelerated change window within days is reasonable. Move to hours if exploitation is reported.
  3. Install the update on all Exchange servers and on all servers and workstations running the Exchange Management Tools, as Microsoft recommends, to keep management tools and servers compatible.
  4. Read Microsoft’s deployment guidance before rollout, as the release was unusually sequenced.
  5. Hunt through audit logs for the activity above, and enforce multi-factor authentication to reduce the value of stolen credentials.
  6. Tell the messaging and security teams, and document the patch level once done.

Microsoft has not said whether any workaround exists. Patching is the only fix described in the sources.

Sources

Similar Posts