CVE-2026-96940
CVSS 8.8 HIGH: weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network. Microsoft patch: 5129957.
Patch available KB5129957
Vulnerabilities · 6h ago
Microsoft has pushed an out-of-band Exchange Server update for CVE-2026-96940, a high-severity mailbox-access flaw that can let an authenticated user read other users’ email and attachments in the same organization. Microsoft also says it has already applied a related service-side fix in Exchange Online.
The bug is in Exchange’s authorization checks: once a user is already signed in, the server can fail to keep mailbox boundaries straight and grant access where it should not. Microsoft says the issue does not cross tenant boundaries, but on-prem systems still need the September 2026 v2 security update across supported Exchange servers and Exchange Management Tools.
That leaves the real exposure on the customer side, not the cloud side. If an organization runs Exchange on-prem and has not moved to the new build, ordinary authenticated accounts can inherit access they were never meant to have, and existing mailbox-permission assumptions no longer hold.
CVSS 8.8 HIGH: weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network. Microsoft patch: 5129957.
Patch available KB5129957
2 sources covering this story
Microsoft released out-of-band Exchange Server security update that fixes a high-severity mailbox access vulnerability (CVE-2026-96940).
Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server 2016 Cumulative Update 23: >= 1
Part of the PlainSec briefing for 2026-10-05