Microsoft Exchange CVE-2026-96940 Lets Authenticated Users Read Other Mailboxes
Microsoft has just released, outside its usual schedule, a patch for an Exchange Server security flaw that allows an authenticated user to read their colleagues' emails. Here's what you need to know.
Microsoft has released new out-of-band security updates for Exchange Server. They fix the vulnerability CVE-2026-96940, associated with a CVSS score of 8.8 out of 10 and allowing privilege escalation. "Insufficient authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges on the network", Microsoft says in its advisory.
In practice, an attacker who is already authenticated can exploit this security flaw to access the mailboxes of other users within the same organization. They can then read their emails and any attached files. Even though this is limited to the Exchange Server perimeter itself, it is still a serious issue...
More importantly, a single compromised account, via phishing or a password-spraying attack, would be enough to read someone else's mailbox. It could be the CEO's inbox, the CIO's, or even the accountant's.
No in-the-wild exploitation is known at this time, but Microsoft notes: "Exploitation more likely". In other words, it is not impossible that the security flaw will be exploited soon. On the cloud side, Microsoft has already deployed a fix for Exchange Online: Microsoft 365 customers do not need to take any action. In hybrid mode, you must patch your on-premises Exchange server.
Which Exchange Server versions are affected?
Microsoft chose to release version 2 (V2) of the existing security updates. That is somewhat surprising. These packages include the eight CVEs fixed in September 2026 and add CVE-2026-96940. What you need to understand is that even if you already installed the September update, you still need to go through maintenance again.
Here are the KBs corresponding to each version:
- Exchange Server SE RTM : SU10V2, namely KB5129955
- Exchange Server 2019 CU15 : SU11V2, namely KB5129956
- Exchange Server 2019 CU14 : SU14V2, namely KB5129957
- Exchange Server 2016 CU23 : SU25V2, namely KB5129958
Once the update is installed, Microsoft recommends running the Exchange Server Health Checker script to verify that everything is in order. By the way, while we're talking about this V2 release, there is a known issue that has been reported: a calendar published in .ics format can return an HTTP 500 error to calendar applications.
Exchange 2016 and 2019: no ESU, no patch
As a reminder, support for Exchange Server 2016 and 2019 ended on October 14, 2025. Updates for these two versions are reserved for organizations enrolled in the Extended Security Updates (ESU) Period 2 program, which runs until the end of October 2026.
So if you are still on Exchange 2016 or 2019 without ESU, you will not get this patch. And it is too late to enroll now. If you want to stay with Microsoft's solution, there is one viable option left: migrate to Exchange Server SE (or to Exchange Online).
For more information, see this page.


