550/69 Wednesday, October 7, 2026

Microsoft has released an emergency security update to address a high-severity vulnerability affecting Microsoft Exchange Server. The vulnerability could allow a malicious actor to elevate access privileges and gain unauthorized access to sensitive information. This issue directly affects organizations that continue to operate on-premises email servers and is considered particularly significant because, if left unpatched, it could lead to the exposure of internal communications and confidential business information.
The vulnerability, tracked as CVE-2026-96940, has a CVSS score of 8.8 and is caused by an improper access control weakness. It could allow an attacker who has already authenticated to the system to elevate privileges over the network and access emails and attachments stored in other users’ mailboxes within the same organization. However, the vulnerability cannot be exploited to access data across different organizations. Affected products include Exchange Server Subscription Edition RTM, Exchange Server 2016 Cumulative Update 23, Exchange Server 2019 Cumulative Update 15, and Exchange Server 2019 Cumulative Update 14. For organizations using Exchange Online, Microsoft has already addressed the issue on the server side. Although there are currently no reports of active exploitation, the vulnerability is assessed as having a high likelihood of being weaponized in future attacks.
Administrators of organizations using affected versions of on-premises Microsoft Exchange Server are therefore advised to promptly review their systems and install the latest security updates to remediate the vulnerability and reduce the risk of unauthorized access to sensitive information. Organizations should also regularly review system logs and monitor for unusual cross-mailbox access activity. Keeping systems fully updated remains one of the most important fundamental measures for reducing exposure to potential cyber threats.
Source https://thehackernews.com/2026/10/microsoft-exchange-flaw-lets.html
