Microsoft has issued out-of-band security updates to fix a critical vulnerability in Microsoft Exchange Server that may enable an attacker to escalate their privileges under specific circumstances.
This vulnerability, identified as CVE-2026-96940, has a CVSS score of 8.8.
According to an advisory published on October 2, 2026, Microsoft stated, “Weak authorization in Microsoft Exchange Server permits an authenticated attacker to elevate privileges over a network.”
The tech giant noted that an authenticated attacker could exploit this vulnerability to gain unauthorized access to the mailboxes of other users within the same organization, allowing them to read emails and attachments. However, this flaw does not permit cross-tenant access.
Microsoft has already implemented a related service-side fix for Exchange Online to resolve the issue, meaning that customers using Exchange Online do not need to take any further action.
Users of the affected on-premises Microsoft Exchange Server products are encouraged to install the updates to ensure their protection. The versions affected include:
- Microsoft Exchange Server Subscription Edition RTM
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Update 15
- Microsoft Exchange Server 2019 Cumulative Update 14
Microsoft researcher Jan Mitchell has been credited with discovering and reporting this vulnerability. While there is currently no evidence that the flaw has been exploited in the wild, Microsoft has classified it with an Exploitability assessment of “Exploitation More Likely,” highlighting the urgency for users to promptly apply the necessary fixes.
This announcement follows a warning from Broadcom-owned Symantec, which indicated that the China-linked Warlock actor is taking advantage of multiple vulnerabilities in Microsoft SharePoint to deploy its ransomware in attacks aimed at organizations in Portuguese- and Spanish-speaking regions.
Source: Original article
