Exchange CVE-2026-96940 Lets Any Mailbox User Read Others' Mail, and Patched Servers Need V2
Security / news
Exchange CVE-2026-96940 Lets Any Mailbox User Read Others' Mail, and Patched Servers Need V2
Microsoft's out-of-band September V2 update closes an 8.8-rated authorization flaw in on-premises Exchange, with four KBs and a support cliff for 2016 and 2019.

An authenticated user with an ordinary mailbox in an on-premises Exchange organization can read other users' mail and attachments in that organization, through CVE-2026-96940 (CVSS 8.8), and the fix is a second build of the September update that has to be installed even on servers that already took the first. Microsoft disclosed the flaw on Oct. 2 and says it has seen no active exploitation.
It does not cross tenants, and Exchange Online needed no customer action because Microsoft fixed the service side. Microsoft rates exploitation "more likely."
Which builds and KBs to install
The affected releases are Exchange Server Subscription Edition RTM, Exchange 2019 CU14 and CU15, and Exchange 2016 CU23. Born's Tech and Windows World lists the build numbers and KBs for the September 2026 V2 package:
| Release | Build | Update |
|---|---|---|
| Exchange SE RTM | 15.02.2562.053 | KB5129955 |
| Exchange 2019 CU15 | 15.02.1748.053 | KB5129956 |
| Exchange 2019 CU14 | 15.02.1544.048 | KB5129957 |
| Exchange 2016 CU23 | 15.01.2507.075 | KB5129958 |
The original September update shipped on Sept. 8. Microsoft says V2 must also go onto systems that already have it, which is the line most likely to be missed, because a server showing the September patch looks done. Hybrid operators have to update every on-premises server and every workstation running the Exchange management tools, not only the mailbox servers.
What an attacker needs and what they get
The preconditions are narrow in one direction and wide in the other. The attacker needs a regular authenticated account and network reach to Exchange, with no admin rights. Microsoft's advisory, as reported by Security Affairs, describes weak authorization that lets that account gain higher privileges, with mailbox content and attachments of other users in the same organization exposed.
The score is a fair summary of the access but says nothing about how far it spreads. Any compromised employee credential, such as one from a phished or reused password, becomes a route to every other mailbox in the organization.
Microsoft found the bug internally. Security Affairs and SOC Prime both credit Microsoft researcher Jan Mitchell, and details were not published before the fix. SOC Prime reports that no verified public proof of concept was found. Born reports that CISA's report on the flaw is dated Oct. 6 and that the CVE was not yet in its Known Exploited Vulnerabilities catalog.
Known side effects and the support deadline
Microsoft's release carries documented side effects, according to Born: HTTP 500 errors for .ics calendar links, free/busy problems for delegated mailboxes in pure Graph hybrid setups, and a processing stall caused by missing Korean word-breaking rules. Microsoft recommends running the Exchange Server Health Checker after installing.
Exchange 2016 and 2019 left regular support on Oct. 14, 2025. Born says they receive security updates only through ESU Phase 2, which runs from May to the end of October 2026 and will not be extended. SOC Prime, citing CyberPress, says those organizations must be enrolled in Period 2 to receive the relevant patches.
Related email-security reporting on this site covers Cisco's Secure Email Gateway root flaw and Fortinet's FortiMail zero-day. For 2016 and 2019 servers the date to watch is the end of October 2026, when Born says ESU Phase 2 closes without an extension.
Sources
More in Security
- 01CISA Gave Agencies Three Days for Five 2015-2023 Bugs, and Four Come With a Forensic Triage OrderThe October 8 additions to the exploited-vulnerabilities catalogue show how BOD 26-04 has changed what a deadline means: the patch is the smaller job.
- 02Apple's CoreGraphics Zero-Day CVE-2026-86950 Has a CISA Deadline of October 13, Not the October 2 Being ReportedTrade coverage gives a three-day federal deadline. The catalogue entry itself carries 14 days and no forensic-triage flag.
- 03Rejetto HFS CVE-2026-61500, Found With Anthropic's Mythos, Was Probed One Day After DisclosureA predictable session-signing key lets an unauthenticated attacker forge an HFS admin cookie and run server-side JavaScript; HFS 3.2.1 has carried the fix since July.
- 04Citrix's Third NetScaler Zero-Day in Seven Days Crashes Appliances Already PatchedCVE-2026-88779 hits SAML-configured NetScaler boxes that had just taken the Sept. 27 fixes, and attackers were already trying to drop a payload through it.