Microsoft has issued emergency out-of-band updates to fix a newly disclosed high-severity vulnerability in Microsoft Exchange Server that could enable attackers with valid credentials to gain elevated privileges and access other users' email accounts under specific conditions.
The security flaw, identified as CVE-2026-96940, carries a CVSS score of 8.8, highlighting its potential impact on affected environments.
According to Microsoft's advisory, the issue stems from a weakness in Exchange Server's authorization mechanisms. An authenticated attacker could exploit the vulnerability over the network to obtain permissions beyond their intended access level.
Successful exploitation allows a threat actor with a legitimate account to access mailboxes belonging to other users within the same organization, exposing email content and file attachments. Microsoft noted that the flaw is limited to the affected organization and cannot be used to access mailboxes across different Microsoft 365 tenants.
To mitigate the risk for cloud-based customers, Microsoft has already rolled out a corresponding service-side fix for Exchange Online, meaning organizations using Microsoft's hosted email platform do not need to take any additional action.
However, administrators running on-premises Exchange deployments are strongly encouraged to apply the newly released security patches. The vulnerability affects the following Exchange versions:
- Microsoft Exchange Server Subscription Edition RTM
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Update 15
- Microsoft Exchange Server 2019 Cumulative Update 14
Microsoft credited security researcher Jan Mitchell for discovering and responsibly reporting the issue.
While there are currently no public reports indicating that CVE-2026-96940 has been exploited in active attacks, Microsoft has classified the bug as "Exploitation More Likely." This assessment suggests that threat actors could develop working exploits, making prompt patching a priority for affected organizations.
The disclosure follows recent warnings from Symantec, a Broadcom company, regarding activity by the China-linked Warlock threat group. Researchers reported that the actor has been leveraging multiple Microsoft SharePoint vulnerabilities to deploy Warlock ransomware against organizations primarily located in Portuguese- and Spanish-speaking regions, underscoring the continuing focus on Microsoft enterprise technologies by sophisticated threat actors.
Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post.
