CVE-2026-96940 hits on-prem Exchange Server
Microsoft fixed an authorization flaw in on-prem Exchange Server that could let users read other mailboxes in the same organization.
Microsoft issued out-of-band updates for on-premises Exchange Server after fixing CVE-2026-96940, a weak authorization flaw that could let an authenticated attacker elevate privileges and read other users’ mailboxes within the same organization. The company said it found the issue internally and had no knowledge of active exploitation.
Microsoft has released out-of-band security updates for on-premises Exchange Server affected by CVE-2026-96940, a weak authorization vulnerability that lets an authenticated attacker elevate privileges over the network. According to the CVE record, the issue carries a CVSS score of 8.8 and affects multiple Exchange Server branches in on-premises deployments.
What does the flaw allow?
The vulnerability can give an authenticated user access to other users’ mailboxes within the same organization, including the ability to read messages and attachments. According to Help Net Security, it does not cross tenant boundaries, so the impact remains contained within a single organization.
The CVE Program identifies the fixed builds as 15.01.2507.075 for Exchange Server 2016 CU23, 15.02.1544.048 for Exchange Server 2019 CU14, 15.02.1748.053 for Exchange Server 2019 CU15, and 15.02.2562.053 for Exchange Server Subscription Edition RTM. The Hacker News also reported that Microsoft had already applied a related service-side fix for Exchange Online, while these new updates target affected on-premises Exchange servers.
What patches did Microsoft release?
Microsoft released out-of-band fixes for Exchange Server Subscription Edition RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23. Cyber Kendra said the updates are KB5129955 for Subscription Edition RTM, KB5129956 for Exchange Server 2019 CU15, KB5129957 for Exchange Server 2019 CU14, and KB5129958 for Exchange Server 2016 CU23.
Neowin said Microsoft advised on-premises administrators to run the Exchange Server Health Checker script to identify which updates they need before installing the corresponding packages. CybersecurityNews added that the September 2026 V2 update folded the CVE-2026-96940 fix into the original security packages for on-premises Exchange Server.
What did Microsoft say about the risk?
Microsoft said it identified CVE-2026-96940 internally and had no knowledge of active exploitation of the vulnerability. That assessment comes as the company distributes patches for on-premises installations and confirms that the issue had already been fixed on the service side in Exchange Online.
The official CVE entry and technical reports published in recent days agree that the focus is on on-premises environments. The material provided does not include any specific impact attribution in Latin America or any confirmed report of active exploitation.
Sources
- CVE Record: CVE-2026-96940cve.org· CVE Program
- Out-of-band Exchange Server update fixes high-severity vulnerabilityhelpnetsecurity.com· Help Net Security
- Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxesthehackernews.com· The Hacker News
- CVE-2026-96940vulnerability.circl.lu· CIRCL Vulnerability-Lookup
- Exchange Flaw CVE-2026-96940 Exposes Users' Mailboxescyberkendra.com· Cyber Kendra
- Microsoft Pushes New Exchange V2 Update After Discovering New Security Flawcybersecuritynews.com· CybersecurityNews
- On-premises Exchange administrators must install V2 security updates to fix elevation flawsneowin.net· NeowinUnverified URL



