Microsoft: an Exchange flaw can read other mailboxes, if you are already signed in
On 2 October 2026, Microsoft publishes early security updates. One CVE: CVE-2026-96940, Exchange Server, base score 8.8, severity Important. An already authenticated attacker can read other mailboxes in the same organization. Microsoft says the flaw is not exploited, and that Exchange Online is already fixed on the service side.

Original AI-generated illustration · SecuFocus
At a glance
Key points
This is not remote takeover with no account. It is an account already inside the organization that can read other mailboxes. We did not test Exchange.
What changes
The October 2026 Early Security Updates document, dated 2 October 2026, contains one Microsoft CVE: CVE-2026-96940, Microsoft Exchange Server Elevation of Privilege. The listed base score is 8.8. The displayed severity is Important. Microsoft writes: publicly disclosed no, exploited no, exploitation more likely.
The description says weak authorization lets an authenticated attacker elevate privileges over a network. The FAQ names the gain: unauthorized access to other mailboxes in the same organization, and the ability to read messages and attachments. No access across tenant boundaries.
What leaves
What leaves, here, is other people’s mail and attachments, read by someone who already has an account. Exchange Online: Microsoft says it has already deployed a service-side fix. Exchange Online customers do not need to act to receive it. On-premises Exchange servers do need the listed updates.
What we did not check
We did not install the updates, and we did not open an Exchange mailbox. The score and the “not exploited” status come from Microsoft’s 2 October 2026 document. A status can change.
The choice
Exchange Online: no install on your side, according to Microsoft. On-premises Exchange: install the update that matches your version, inside your maintenance window. In the description, an account already in the organization is enough to read other mailboxes. That is not a fix to postpone because an attacker would first have to “get in”.
Check and explore
Sources for this article
Numbers connect each reference to the passages that use it. Dates show when the documentation was consulted.
- October 2026 Early Security Updates, Microsoft ↗api.msrc.microsoft.com ·
This article draws on the sources above. The exercises are for you to try on your devices; SecuFocus does not present them as tests carried out by its editorial team. Interfaces and features can change. Method and corrections.
Cite this article
Keep this reference with the article when you save or share it.