Microsoft Ships Out-of-Band Exchange Server Updates for CVE-2026-96940: Authenticated Attackers Can Read Other Users' Mailboxes — Patch Every Server and Management Tools Box

Microsoft Ships Out-of-Band Exchange Server Updates for CVE-2026-96940: Authenticated Attackers Can Read Other Users' Mailboxes — Patch Every Server and Management Tools Box

Microsoft Ships Out-of-Band Exchange Server Updates for CVE-2026-96940: Authenticated Attackers Can Read Other Users' Mailboxes — Patch Every Server and Management Tools Box

Microsoft has released out-of-band security updates for Exchange Server fixing a high-severity vulnerability that lets an authenticated attacker read other users' mailboxes inside the same organization. The flaw, tracked as CVE-2026-96940 (CVSS 8.8), is a weak-authorization bug: "an authenticated attacker can exploit this flaw to gain unauthorized access to other users' mailboxes within the same organization and read email messages and attachments," Microsoft said in an advisory released October 2. Cross-tenant access is not possible — the blast radius is your own organization, which is exactly where the sensitive mailboxes live.

The fix ships as September 2026 V2 Security Updates, a re-release of the monthly SU whose only addition is CVE-2026-96940. Exchange Online customers are already protected: Microsoft deployed a related service-side fix late last week, taking customers by surprise because the update landed without an accompanying KB article. The Exchange Team acknowledged the odd sequence, saying the update "was published ahead of its intended schedule" — without explaining why that happened.

The update covers Exchange Server Subscription Edition RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23. Microsoft credited its own researcher Jan Mitchell with discovering the flaw and said it is "not aware of active exploitation" — but it tagged the bug with an Exploitability assessment of "Exploitation More Likely," and noted that this type of vulnerability has been exploited in the past. Exchange 2016 and 2019 are out of support, so their updates go only to organizations enrolled in the Period 2 Extended Security Update program, which runs through October 2026.

Microsoft's deployment guidance is unusually explicit: install the SUs on all Exchange Servers and on every server and workstation running the Exchange Management Tools, including management-only machines in hybrid environments. SUs are cumulative, so the latest one is enough. Two known issues ship with this release — published .ics calendars can return HTTP 500, and Korean-language mailboxes can hit a ContentEngine deadlock from missing WordBreaker rule files — and the Health Checker script will inventory what needs updating. The Exchange flaw lands the same week attackers were still working over Microsoft's other server flagship: the SharePoint CVE-2026-65660 exploitation wave we covered when it hit CISA's catalog.

What Should You Do?

  1. Install the September 2026 V2 SUs on every Exchange server — SE RTM, 2019 CU14/CU15, 2016 CU23 — without waiting for the next patch cycle; an authenticated mailbox-reading bug rated "Exploitation More Likely" is not a backlog item.
  2. Patch the Exchange Management Tools boxes too. Microsoft's compatibility guidance includes every machine running the tools, even in hybrid environments where Exchange Online handles mail flow.
  3. If you run Exchange 2016 or 2019 outside the Period 2 ESU program, these SUs are your last warning shot — no more fixes are coming; plan the migration to Subscription Edition now.
  4. Audit mailbox access logs for cross-user reads while you patch, and read the two known issues (HTTP 500 on published calendars, Korean-language ContentEngine deadlock) before they get misdiagnosed as attacks.

The WAF Angle

CVE-2026-96940 is weak authorization inside Exchange, not a malformed request a WAF can signature — the patch is the only real fix. What an edge layer can do is narrow the window: OWA, EAC and EWS fronted by a WAF or API gateway should rate-limit authenticated sessions and alert when a single session starts reading across many mailboxes, which is precisely the behavior this flaw enables. The pattern matches the SharePoint wave from September: Microsoft server workloads with weak internal authorization are being treated as high-value targets, and reverse-proxy posture doesn't substitute for SU deployment cadence. If your Exchange admin portals are still exposed to the internet without an edge control in front, this advisory is a good day to fix that too.

Sources