Skip to content
Brief Security & Trust ·

Microsoft ships early Exchange Server update for high-severity mailbox bug

The fix for CVE-2026-96940 came out ahead of schedule, and Microsoft knows of no attacks so far.

In brief
  • Microsoft added a fix for CVE-2026-96940 to its September 2026 Exchange Server updates. It says it knows of no attacks.
  • Help Net Security says the flaw may let a logged-in user read colleagues' email. Servers need the update installed.

Microsoft released a new version of its September 2026 Exchange Server security updates. The only change is a fix for CVE-2026-96940. Help Net Security reported on 5 October that the flaw is rated high severity. It said a user with a valid login might read other people's emails and attachments inside the same organisation. It does not reach across tenants, which are separate customer accounts. The update covers Exchange Server Subscription Edition, 2019 CU14 and CU15, and 2016 CU23.

Microsoft said its own staff found the flaw and that it knows of no active attacks. Help Net Security said Microsoft believes the flaw could be exploited reliably, and that this type of bug has been abused before. Microsoft said the update went out ahead of its planned date. It did not say why. Microsoft's post sends readers to a separate article for details, and says documentation may not be complete yet.

Anyone running their own Exchange servers needs to install the update. Microsoft says this includes machines used only for management tools. Exchange Online customers are already protected. Exchange 2016 and 2019 are out of support, so only customers in Microsoft's paid Period 2 extended program can get this fix for them.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: Microsoft.