By Rabia Noureen
Publication Date: 2026-10-06 17:08:00
Key Takeaways:
- Microsoft has released a new Exchange Server security update to address CVE-2026-96940.
- The vulnerability could allow authenticated users to access other mailboxes within the same organization.
- Organizations running on-premises Exchange Server should install the V2 September 2026 updates.
Microsoft has released an out-of-band security update to address CVE-2026-96940, a high-severity elevation-of-privilege vulnerability in on-premises Microsoft Exchange Server. This flaw stems from weak authorization controls that could allow an authenticated user to gain access to other users’ mailboxes within the same organization.
Attackers could potentially read email messages and attachments without requiring additional user interaction. Microsoft assigned the vulnerability a CVSS score of 8.8 and considers exploitation “more likely,” even though there is currently no evidence of active…



