Microsoft ships out-of-band fix for CVE-2026-96940 in Exchange Server
On October 2, 2026, Microsoft released an out-of-band security update for Exchange Server addressing CVE-2026-96940, an elevation-of-privilege flaw rated CVSS 8.8. An authenticated attacker could read other users' mailboxes within the same organization. Four on-premises branches are affected: Subscription Edition RTM, 2019 CU15 and CU14, and 2016 CU23; Exchange Online is already patched.
- CVSS 8.8 (High), tagged "Exploitation More Likely", not publicly disclosed
- Attack needs only valid credentials, no user interaction required
- Fixes: KB5129955, KB5129956, KB5129957, KB5129958
- Exchange Online unaffected — fix deployed service-side
Read next
Security