SecuFocus
BriefAnnouncements

Microsoft: an Exchange flaw can read other mailboxes, if you are already signed in

On 2 October 2026, Microsoft publishes early security updates. One CVE: CVE-2026-96940, Exchange Server, base score 8.8, severity Important. An already authenticated attacker can read other mailboxes in the same organization. Microsoft says the flaw is not exploited, and that Exchange Online is already fixed on the service side.

Illustration, not an Exchange screenshot.

Original AI-generated illustration · SecuFocus

At a glance

Key points

This is not remote takeover with no account. It is an account already inside the organization that can read other mailboxes. We did not test Exchange.

What changes

The October 2026 Early Security Updates document, dated 2 October 2026, contains one Microsoft CVE: CVE-2026-96940, Microsoft Exchange Server Elevation of Privilege. The listed base score is 8.8. The displayed severity is Important. Microsoft writes: publicly disclosed no, exploited no, exploitation more likely.

The description says weak authorization lets an authenticated attacker elevate privileges over a network. The FAQ names the gain: unauthorized access to other mailboxes in the same organization, and the ability to read messages and attachments. No access across tenant boundaries.

What leaves

What leaves, here, is other people’s mail and attachments, read by someone who already has an account. Exchange Online: Microsoft says it has already deployed a service-side fix. Exchange Online customers do not need to act to receive it. On-premises Exchange servers do need the listed updates.

What we did not check

We did not install the updates, and we did not open an Exchange mailbox. The score and the “not exploited” status come from Microsoft’s 2 October 2026 document. A status can change.

The choice

Exchange Online: no install on your side, according to Microsoft. On-premises Exchange: install the update that matches your version, inside your maintenance window. In the description, an account already in the organization is enough to read other mailboxes. That is not a fix to postpone because an attacker would first have to “get in”.

Check and explore

Sources for this article

Numbers connect each reference to the passages that use it. Dates show when the documentation was consulted.

This article draws on the sources above. The exercises are for you to try on your devices; SecuFocus does not present them as tests carried out by its editorial team. Interfaces and features can change. Method and corrections.

Cite this article

Keep this reference with the article when you save or share it.