Particle.news

Microsoft Issues Emergency Fix for High‑Severity Exchange Mailbox Flaw

Authenticated attackers can access other users' mailboxes, requiring immediate on‑premises updates to prevent data exposure.

Overview

  • Microsoft disclosed the authorization flaw tracked as CVE-2026-96940 on October 2 and pushed an emergency service-side fix for Exchange Online followed by out-of-band patches for on-premises servers.
  • The bug stems from weak authorization in Exchange Server and could let an authenticated attacker read other users' email and attachments inside the same organization.
  • Microsoft rated the vulnerability 8.8 on the CVSS scale and assigned an exploitability assessment of "Exploitation More Likely" while saying it is not aware of active exploitation.
  • On-premises products affected include Exchange Server Subscription Edition RTM, Exchange Server 2016 CU23, and Exchange Server 2019 CUs 14 and 15, and administrators must install the provided security updates plus the September 2026 v2 compatibility update.
  • Microsoft acknowledged a rushed rollout that briefly lacked KB documentation, and administrators should expect possible short-term disruption from updates but reduce the greater risk of mailbox compromise by patching quickly.