Microsoft says the flaw is “more likely” to be exploited, making the latest Exchange Server update a priority for on-premises deployments.
Key Takeaways:
Microsoft has released an out-of-band security update to address CVE-2026-96940, a high-severity elevation-of-privilege vulnerability in on-premises Microsoft Exchange Server. This flaw stems from weak authorization controls that could allow an authenticated user to gain access to other users’ mailboxes within the same organization.
Attackers could potentially read email messages and attachments without requiring additional user interaction. Microsoft assigned the vulnerability a CVSS score of 8.8 and considers exploitation “more likely,” even though there is currently no evidence of active attacks.
For organizations running vulnerable Exchange Server deployments, successful exploitation could expose sensitive business communications, attachments, and potentially confidential information stored in employee mailboxes. This flaw does not enable cross-tenant access, but it presents a significant insider-risk scenario because any attacker who obtains valid credentials could potentially move beyond their authorized mailbox access. This vulnerability affects Exchange Server Subscription Edition as well as supported Exchange 2016 and Exchange 2019 builds still receiving security updates.
Microsoft released its September 2026 Exchange Server security updates as a V2 release that includes protection against the CVE-2026-96940 vulnerability. Administrators should install the new updates even if they previously deployed the original September patches, as those earlier updates did not contain the fix.
Exchange Online customers are already protected through a service-side mitigation and do not need to take action. However, organizations with hybrid environments must update all on-premises Exchange servers, including systems used for management purposes and machines running Exchange Management tools.
Microsoft has warned that applying the V2 updates reduces the risk of unauthorized mailbox access, but it may create additional work for IT teams. Organizations still running Exchange Server 2016 or 2019 can only obtain these fixes through Microsoft’s Period 2 Extended Security Update (ESU) program, which requires separate licensing.
Businesses that have not enrolled in the program may need to accelerate migration plans to Exchange Server Subscription Edition to maintain security coverage. Administrators should also be aware of known issues associated with the release, including reported problems with published calendar links and certain Korean-language mailbox scenarios that Microsoft plans to address in future updates.