Skip to content
Security & Trust

Microsoft Exchange flaw can let a logged-in user read colleagues' email

CVE-2026-96940 is fixed automatically in Exchange Online. On-premises customers have to install the patch themselves.

W
WebPulse Newsroom
AI-assisted · 3 min read
Share on X LinkedIn
Microsoft Exchange flaw can let a logged-in user read colleagues' email
In brief
  • Microsoft says CVE-2026-96940 could let an authenticated Exchange user, under certain conditions, read other users' mailboxes in the same organization. It does not allow cross-tenant access.
  • Exchange Online is already fixed. On-premises customers running four listed versions must install the update themselves.
  • Microsoft sees no exploitation in the wild but rates it "Exploitation More Likely". Confirm your Exchange build and patch status this week.

Two companies can read the same Microsoft advisory on the same day and face very different weeks. One does nothing, because the fix is already live. The other has a patch to test, schedule and install. The Exchange flaw disclosed this week shows that gap clearly.

What Microsoft disclosed

Microsoft released out-of-band updates for Exchange Server. That means a fix outside its regular update cycle. The flaw is tracked as CVE-2026-96940 and scores 8.8 on the CVSS severity scale. The Hacker News reported the details on October 5. Microsoft's advisory is dated October 2, 2026.

Microsoft describes the problem as "weak authorization" that lets an authenticated attacker elevate privileges over a network. The Hacker News reports that the flaw could allow this under certain conditions. In practice, the attacker can reach other users' mailboxes in the same organization. They can read email messages and attachments. Microsoft says the flaw does not allow access across tenants, meaning between separate organizations.

8.8
CVSS severity score
Source: Microsoft advisory, as reported by The Hacker News (October 5, 2026)

How the flaw works

Two checks protect a mailbox. Authentication asks who you are. Authorization asks what you are allowed to open. This flaw sits in the second check.

Think of a hotel keycard. It proves you are a guest, and it should open only your room. A weak authorization flaw is a card that also opens other rooms on the floor.

That is why "authenticated" should not reassure anyone. The attacker needs a valid login. But once inside, the system fails to stop them from reaching colleagues' mail. A single compromised account could become a route to many mailboxes. That is our reading of the mechanism, not a claim Microsoft makes.

The reports leave out some detail. They do not say what level of account the attacker needs. They do not say what the "certain conditions" are or how the exploit works. Teams should not assume the bar is high.

Cloud customers wait. Server owners work.

Microsoft has already deployed a "related service-side fix" to Exchange Online. Those customers need to take no action.

On-premises customers carry the whole job. Four versions are listed as affected: Exchange Server Subscription Edition RTM, Exchange Server 2016 Cumulative Update 23, and Exchange Server 2019 Cumulative Updates 14 and 15.

4
Affected on-premises Exchange versions listed
Source: The Hacker News (October 5, 2026)

Microsoft's assessment adds urgency. It found no evidence of exploitation in the wild. But it tagged the flaw "Exploitation More Likely". Microsoft credits its own researcher, Jan Mitchell, with finding and reporting it.

Exploitation More Likely
Microsoft exploitability assessment
Source: Microsoft advisory, as reported by The Hacker News (October 5, 2026)

The wider context

The Hacker News also notes that Symantec recently warned of the China-linked Warlock actor. It said the group is exploiting multiple Microsoft SharePoint vulnerabilities to deploy ransomware. Those attacks target organizations in Portuguese- and Spanish-speaking countries. The report does not link that activity to this Exchange flaw. It does show that Microsoft server software such as SharePoint is an active target.

Questions to put to your team

First, do we run Exchange on our own servers, and which cumulative update is each one on? Compare every build against the four listed versions.

Second, who owns the patch, and what is the date it will be installed? Out-of-band updates skip the normal monthly rhythm, so someone must schedule them on purpose.

Third, if we run a mix of cloud and on-premises mail, which mailboxes sit on servers we still maintain? Ask your administrators to confirm scope against Microsoft's advisory.

Fourth, can we spot one account reading many mailboxes? Check whether your logging would show it.

Moving mail to the cloud does not remove risk. It moves the patching work to the vendor. For everyone still hosting their own servers, the patch is theirs to install.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: The Hacker News.

Share this insight