Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Oct 06, 2026 · 8 min read

CVE-2026-96940: Exchange Flaw Lets Users Read Others' Mail

On October 2, 2026, Microsoft released an early fix for a weak authorization bug in on premises Exchange Server that lets any signed in user open coworkers' mailboxes and attachments. Exchange Online is already fixed. Exchange 2016 and 2019 servers can only get the patch through a paid support program that ends this month.

Every Exchange organization has accounts nobody worries about: the summer intern, the shared reception login. CVE-2026-96940 turns any of them into a key to everyone else's inbox. Microsoft says an authenticated attacker who exploits it "could gain unauthorized access to other users' mailboxes within the same organization and read email messages and attachments."

Nobody is known to be exploiting it yet. Microsoft still rates it "Exploitation More Likely," and for Exchange 2016 and 2019 the patch sits behind a support contract that expires at the end of October.

Key Takeaways

  • CVE-2026-96940 is a CVSS 8.8 elevation of privilege flaw in on premises Exchange Server that lets an authenticated user read other users' mailboxes and attachments inside the same organization, but not across tenants.
  • Microsoft released fixes on October 2, 2026 for Exchange SE RTM, Exchange 2019 CU14 and CU15, and Exchange 2016 CU23; Exchange Online is already fixed service side.
  • Microsoft rates the bug "Exploitation More Likely" but found it internally, credits Jan Mitchell from Microsoft, and is not aware of active exploitation.
  • Exchange 2016 and 2019 updates reach only organizations enrolled in the Period 2 Extended Security Update program, which runs through the end of October 2026 with no further extensions planned.
  • GDPR defines unauthorized access to personal data as a personal data breach, and MailItemsAccessed, the audit signal Microsoft recommends for proving which emails were read, exists only in Exchange Online.
A row of closed server racks in a dim data center with one storage unit door standing ajar, exposing the drives inside

What Is CVE-2026-96940?

CVE-2026-96940 is a flaw in Microsoft Exchange Server that lets a signed in user step outside their own mailbox and read other people's mail. The MSRC Security Update Guide entry describes it in one line: "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network." Its FAQ adds the limit that matters for cloud tenants: the vulnerability "does not allow access across tenant boundaries."

Microsoft's CVSS 3.1 vector explains the 8.8 score: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. Network reachable, low complexity, low privileges, no user interaction. Microsoft rates the severity Important, not Critical.

One detail in the record does not add up. The CVE.org entry pairs "weak authorization" with CWE-1390, "Weak Authentication." Authentication decides who you are; authorization decides what you may touch. A logged in user reading someone else's mailbox reads like an authorization failure, but Microsoft has published no technical detail that settles it. CISA's enrichment on the same record scores exploitation "none," automatable "no," and technical impact "total."

Microsoft's October 2026 security update data credits "Jan Mitchell from Microsoft," and the Exchange team says: "We identified the vulnerability internally and are not aware of active exploitation."

Which Exchange Servers Are Affected?

Every on premises Exchange build line still receiving updates is affected until it gets the October 2 security update; Exchange Online is not. Microsoft lists four products, each with its own KB and the first fixed build:

  • Exchange Server Subscription Edition RTM: KB5129955, fixed in build 15.02.2562.053
  • Exchange Server 2019 CU15: KB5129956, fixed in build 15.02.1748.053
  • Exchange Server 2019 CU14: KB5129957, fixed in build 15.02.1544.048
  • Exchange Server 2016 CU23: KB5129958, fixed in build 15.01.2507.075

For cloud customers, MSRC says "Microsoft has already deployed a related service-side fix to Exchange Online" and no action is needed. Hybrid shops are not off the hook. The Exchange team's release post says the update "needs to be installed on your Exchange servers, even if they are used only for management purposes," and recommends patching workstations that run the Exchange Management Tools too.

The timing was unusual. Microsoft shipped the fix as "September 2026 V2" rather than waiting for Patch Tuesday on October 13, conceding it "was published ahead of its intended schedule." It did not say why.

Why Does "Authenticated Only" Still Matter?

Because the hard part of this attack, getting one valid login, is something attackers already manage all the time. The Verizon 2026 Data Breach Investigations Report found phishing was the initial access vector for 16% of breaches and credential abuse for 13%, according to SC Media's summary. Together that is 29% of breaches starting from exactly the foothold CVE-2026-96940 needs.

Insiders need no phishing at all. A departing salesperson who wants the customer list already holds a working account, and this flaw removes the check that keeps that account inside its own mailbox.

This is the fourth Exchange flaw we have tracked in 2026 whose payoff is mailbox access. CVE-2026-42897 in May needed a victim to open a crafted message in Outlook Web Access. In July, CVE-2026-54998 let a low privileged Exchange Online account climb toward admin, but Microsoft fixed it inside its own cloud. CVE-2026-62911 in August needed an authentication relay. CVE-2026-96940 needs only an ordinary login, on servers customers must patch themselves.

Is This the Last Patch Exchange 2016 and 2019 Will Get?

Only Exchange 2016 and 2019 customers holding a second paid support contract can patch this bug, and they are near the end of the line. Both versions reached end of support on October 14, 2025. Microsoft then sold a paid Extended Security Update bridge, and in April 2026 it announced a Period 2 running "from the start of May 2026 through the end of October 2026." Its wording was blunt: "There will be no further extensions of this program after that."

The October 2 post makes the gate explicit: 2016 and 2019 fixes require being "enrolled into the Period 2 ESU program," which needs a Microsoft Enterprise Agreement and a fresh purchase even for Period 1 customers. Everyone else is told to "migrate to Exchange Server Subscription Edition (SE)."

The calendar is tight. The same DBIR found the median time to fully remediate CISA's known exploited flaws grew from 32 to 43 days. Forty three days after October 2 is November 14, two weeks after Period 2 ends. The next Exchange bug disclosed after October will have no patch for 2016 or 2019, ESU contract or not.

What This Means for Your Inbox

Read access to a mailbox is often worth more than control of the server it sits on. A work mailbox holds contracts, payroll attachments, HR cases and legal advice. It also holds password reset emails for every cloud service tied to that address, so one readable inbox can become a string of account takeovers.

It is also the raw material of business email compromise. An intruder reading a finance team's threads learns invoice formats and who approves payments before sending a single message. We saw the server wide version of that threat in August, when 21,899 Exchange servers were still open to a mailbox hijack bug. CVE-2026-96940 brings the same payoff within reach of anyone with a login.

If your employer runs Exchange on its own servers, a colleague may be able to read your work mail until IT installs this update. Keep personal medical and financial email out of it.

Would Exploitation Be a Reportable GDPR Breach?

An unpatched vulnerability is not a breach by itself, but confirmed or probable unauthorized reading of mailboxes almost certainly is. GDPR Article 4(12) defines a personal data breach as "a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data." Mailboxes are full of personal data.

Article 33(1) then requires notifying the supervisory authority "without undue delay and, where feasible, not later than 72 hours after having become aware of it," unless the breach "is unlikely to result in a risk to the rights and freedoms of natural persons." Article 33(5) requires documenting every breach, reported or not. Whether an incident crosses the risk threshold is a call for your DPO and counsel.

The harder problem is evidence. Microsoft's own Purview guidance on compromised accounts warns that "you might face regulatory fines unless you can prove that sensitive information wasn't exposed." Its recommended tool, the MailItemsAccessed audit action, is an Exchange Online feature. On premises, mailbox audit logging is switched on per mailbox, keeps entries for 90 days by default, and records MessageBind, the event for opening an item, only for the admin logon type. Microsoft has not said how exploitation of this bug shows up in those logs, if at all.

Regulators have already punished the insider version of this story. Italy's privacy regulator fined Intesa Sanpaolo €31.8 million after one employee viewed 3,573 customers' data from February 2022 to April 2024 without internal controls noticing, and The Record reported that notifications "came after legally required deadlines." Swap the bank database for an Exchange mailbox store and the exposure looks the same.

What Should Exchange Admins Do Right Now?

Patch every on premises Exchange server, then make sure you could prove who read what.

  1. Inventory first. Run Microsoft's Exchange Health Checker, which the Exchange team says "will tell you if any of your Exchange Servers are behind on updates."
  2. Install the October 2 update and confirm the build. Every server, including hybrid management servers and Management Tools machines, should report at least the fixed build listed above.
  3. Without Period 2 ESU, plan the exit now. MSRC lists no workaround or mitigation, only the updates. Upgrade to Exchange SE, which Microsoft recommends doing in place from 2019, or move mailboxes to Exchange Online.
  4. Turn on mailbox auditing and keep logs longer. Check with Get-Mailbox -ResultSize Unlimited | Format-List Name,Audit*. Enable it with Set-Mailbox -AuditEnabled $true and raise AuditLogAgeLimit above the 90 day default.
  5. Hunt for cross mailbox access. Use Search-MailboxAuditLog, New-MailboxAuditLogSearch or the non owner mailbox access report, and look for FolderBind events by accounts with no business reason to be there.
  6. Shrink the pool of usable accounts. Disable dormant and shared logins, reset passwords tied to recent phishing reports, and review Full Access grants with Get-MailboxPermission.
  7. Write it down. Keep the patch date, build evidence and audit results. If an incident surfaces later, that file starts your Article 33(5) record.

No exploit is known today, but every Exchange organization already has the precondition: user accounts. For Exchange 2016 and 2019, the window to receive any fix at all closes at the end of October.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.