Critical Exchange Flaw Lets Authenticated Users Read Other Mailboxes

Microsoft has issued an emergency patch for a serious vulnerability in Microsoft Exchange Server that lets authenticated users access other people’s mailboxes within the same organization. The flaw, tracked as CVE-2026-96940, carries a high severity rating of 8.8 out of 10. It stems from weak authorization controls in certain Exchange Server versions. (Publish date: October 2, 2026)

What It Does and Who’s Affected

An attacker who already has valid credentials can exploit this vulnerability to view email content and attachments in other accounts tied to the same on-premises Exchange deployment. Importantly, this does not allow access across separate tenants, so the exposure is contained to within single organizations. Microsoft has already deployed a server-side fix for Exchange Online, meaning customers using the cloud version aren’t at risk and don’t need to take further action.

The on-premises versions vulnerable include:

  • Microsoft Exchange Server Subscription Edition RTM
  • Microsoft Exchange Server 2016 Cumulative Update 23
  • Microsoft Exchange Server 2019 Cumulative Update 14 and 15

These versions are advised to apply the security update immediately. The flaw was discovered and reported by researcher Jan Mitchell. While there’s no public evidence yet that the flaw has been used in real-world attacks, Microsoft has flagged the exploitability as “Exploitation More Likely,” underlining the urgency of patching.

Why It Matters

Email systems are a cornerstone for business operations. A breach in Exchange Server can give attackers access to sensitive or confidential information, enabling everything from internal espionage to broader social engineering campaigns. The fact that this vulnerability can be triggered with valid credentials means that existing user accounts—whether compromised or legitimate—could be leveraged. That dynamic makes this far more dangerous than purely technical exploits requiring external access or complex setups.

This disclosure also coincides with other Microsoft advisories—just days earlier, there were warnings about ransomware attacks tied to SharePoint vulnerabilities being exploited by the China-linked Warlock group in Portuguese- and Spanish-speaking regions. Together, these weaknesses show growing pressure on enterprise email and collaboration systems.

By exposing a path for privilege escalation via weak authentication checks, this bug underscores recurring concerns about legacy on-prem software security. Many organizations lag in patching cumulative updates or managing hybrid environments, leaving doors open for attackers. This incident reflects the kinds of threats emerging in the broader industry as cloud transition mixes with legacy infrastructure.

In short: if you run any of the listed on-premises Exchange versions, patch now. Online users are already protected, but staying vigilant about account credentials and access controls remains crucial.

Analytical Insight: This vulnerability highlights how “authenticated” doesn’t always mean “trusted.” It’s now clear that firms need to assume some user accounts may be compromised—or that insiders may misuse access. Zero-trust strategies, least privilege models, and rigorous monitoring of mailbox activity will increasingly become non-optional. Microsoft’s proactive disclosure and patching are standard, but they serve as a reminder: legacy software still presents high risks, and patch management in the hybrid enterprise will only get more critical as threats evolve.