Microsoft patches high-severity Exchange Server flaw
Microsoft issued an urgent fix for CVE-2026-96940, a privilege-escalation bug in on-premises Exchange Server that could expose other users' mailboxes.
Microsoft released an out-of-band security update for on-premises Exchange Server on October 2, 2026, fixing a high-severity privilege-escalation vulnerability tracked as CVE-2026-96940.
The flaw carries a severity rating of 8.8 out of 10. According to Microsoft, an authenticated attacker could exploit weak authorization to escalate privileges over a network and read other users' mailboxes within the same organization. The bug cannot be used for cross-tenant access.
Microsoft said there is no evidence the flaw has been abused in the wild, and labeled the vulnerability as "exploitation more likely." The U.S. Cybersecurity and Infrastructure Security Agency (CISA) does not list CVE-2026-96940 in its Known Exploited Vulnerabilities catalog.
Exchange Online users are already protected by a service-side fix. Organizations running on-premises Exchange Server are advised to upgrade to the latest version.
September V2 updates
The patch arrived as part of the September 2026 V2 Exchange Server Security Updates. The original September updates were released on September 8, 2026, and Microsoft said the main difference in the V2 release is the fix for CVE-2026-96940, pushed ahead of its intended schedule.
Exchange Server 2016 and Exchange Server 2019 reached end of support in 2025. The latest security updates are only available to organizations enrolled in Microsoft's Period 2 Extended Security Update (ESU) program, which covers updates released between May and the end of October 2026.
Quick answers
What is CVE-2026-96940?
It is a high-severity (8.8/10) weak authorization privilege-escalation vulnerability in Microsoft Exchange Server that could let an authenticated attacker read other users' mailboxes within the same organization.
Are Exchange Online users affected?
No. Exchange Online users are already secured by a service-side fix. The update applies to on-premises Exchange Server.
Who can get the latest Exchange Server security updates?
The latest updates are only available to organizations enrolled in Microsoft's Period 2 Extended Security Update (ESU) program, which covers updates released between May and the end of October 2026.