Microsoft ships out-of-band Exchange Server fix for high-severity mailbox bug
Microsoft released an out-of-band Exchange Server update fixing CVE-2026-96940, a high-severity flaw that could let authenticated attackers read other users' emails and attachments within the same organization, though not across tenant boundaries. No active exploitation is known, but Microsoft urges admins to patch promptly.
- CVE-2026-96940 lets authenticated attackers read colleagues' mail and attachments
- Access across tenant boundaries is not possible
- Patch covers Exchange Server Subscription RTM, 2019 CU14/15 and 2016 CU23
- Exchange Online received a related service-side fix earlier
Read next
Software