By Guru Baran
Publication Date: 2026-10-03 14:59:00
Microsoft has released September 2026 V2 security updates to fix an Exchange Server flaw that lets authenticated attackers access other users’ mailboxes within the same organization. Tracked as CVE-2026–96940, the vulnerability could expose email messages and attachments, making it a serious concern for businesses running Exchange on-premises.
The flaw involves weak authorization, allowing an attacker with authenticated access to gain privileges over a network. Public vulnerability records list a CVSS score of 8.8. Unlike attacks that require someone to open a malicious file, exploitation does not require user interaction. The reported mailbox access does not extend across tenant boundaries.
Microsoft said its own teams discovered the vulnerability internally and were not aware of active exploitation. The company also confirmed that the update appeared ahead of its planned release schedule, and some supporting documentation may have been unavailable when the announcement…

