Select a theme from the list.
Insights

From our experts

Latest
Emergency Exchange Update Closes a Door Into Other Users' MailboxesApple Moves to Rein In AI Agents With Sweeping Mac Data AccessPredictable Session Keys Put Rejetto File Servers on the Attack RadarMicrosoft X Account Hijack Shows How Brand Trust Can Become a Cyber WeaponFortra BoKS Flaws Put the Keys to Unix and Linux Fleets at RiskShinyHunters Detention Could Expose the People Behind a Global Extortion NetworkTerminalFix Lures Turn Victims Into Gateways for Covert Network AccessCritical Dell Storage Flaws Put Kubernetes Clusters and Backend Arrays at RiskDTU Identity System Breach Puts Two Decades of Personal Data at RiskPhishing Campaign Turns Legitimate RMM Software Into a Double BackdoorAndroid 17 Closes a Favorite Doorway for Banking MalwareFrontline Education Breach Exposes Sensitive School Employee RecordsEmergency Exchange Update Closes a Door Into Other Users' MailboxesApple Moves to Rein In AI Agents With Sweeping Mac Data AccessPredictable Session Keys Put Rejetto File Servers on the Attack RadarMicrosoft X Account Hijack Shows How Brand Trust Can Become a Cyber WeaponFortra BoKS Flaws Put the Keys to Unix and Linux Fleets at RiskShinyHunters Detention Could Expose the People Behind a Global Extortion NetworkTerminalFix Lures Turn Victims Into Gateways for Covert Network AccessCritical Dell Storage Flaws Put Kubernetes Clusters and Backend Arrays at RiskDTU Identity System Breach Puts Two Decades of Personal Data at RiskPhishing Campaign Turns Legitimate RMM Software Into a Double BackdoorAndroid 17 Closes a Favorite Doorway for Banking MalwareFrontline Education Breach Exposes Sensitive School Employee Records
Security Insight

Emergency Exchange Update Closes a Door Into Other Users' Mailboxes

Emergency Exchange Update Closes a Door Into Other Users' Mailboxes
Photo by cottonbro studio on Pexels

Microsoft has released revised Exchange Server security updates that add protection for CVE-2026-96940, a high-severity authorization flaw. An authenticated attacker could use the vulnerability to obtain elevated access and read email or attachments belonging to other users in the same organization.

News Date: 2026-10-02

Microsoft has issued a second version of its September 2026 Exchange Server security updates after adding protection for CVE-2026-96940, a high-severity authorization vulnerability affecting on-premises deployments.

The flaw carries a CVSS score of 8.8 and requires an attacker to possess valid credentials. Successful exploitation can allow the intruder to elevate privileges across the network and obtain unauthorized access to other users' mailboxes within the same organization. Messages and attachments could consequently become available to an account that should not have permission to read them.

Why Authenticated Flaws Still Matter

The authentication requirement reduces exposure to anonymous internet attacks, but it should not be mistaken for a strong protective boundary. Phishing, password reuse, information-stealing malware and compromised service accounts routinely provide criminals with valid Exchange credentials.

Once inside, an attacker could use the vulnerability to move beyond the original mailbox and collect sensitive executive communications, legal correspondence, financial records or password-reset messages. Email also contains valuable intelligence that can support more convincing impersonation and business email compromise attacks.

Microsoft says it discovered the vulnerability internally and has not identified active exploitation. The company nevertheless classified exploitation as more likely, making rapid remediation important for organizations operating affected servers.

Who Needs to Act

The affected products include Exchange Server Subscription Edition RTM and specific Exchange Server 2016 and 2019 cumulative updates. Access to new fixes for the older editions may depend on enrollment in Microsoft's Extended Security Update program because those products are outside normal support.

Exchange Online has received a service-side correction, so cloud-only customers do not need to deploy this server update. Hybrid organizations must still examine any on-premises Exchange servers and management-tools workstations remaining in their environment.

Defensive Priorities

  • Install the revised Exchange security update on every eligible server.
  • Verify deployment with the Exchange Server Health Checker.
  • Reacquire updated compliance metadata if using the affected offline Scan Cab.
  • Review mailbox access logs for unusual cross-user activity.
  • Disable dormant accounts and investigate recent credential compromises.

In my view, the unusual out-of-band release sequence is itself a reason to check update status carefully. Administrators who deployed the original September package may reasonably assume they are protected, even though the revised release contains additional security coverage. Patch verification, not simply patch deployment, is the essential control in this situation.

Talk to our team →

Latest

Emergency Exchange Update Closes a Door Into Other Users' MailboxesOct 6, 2026Apple Moves to Rein In AI Agents With Sweeping Mac Data AccessOct 6, 2026Predictable Session Keys Put Rejetto File Servers on the Attack RadarOct 6, 2026Microsoft X Account Hijack Shows How Brand Trust Can Become a Cyber WeaponOct 5, 2026Fortra BoKS Flaws Put the Keys to Unix and Linux Fleets at RiskOct 5, 2026ShinyHunters Detention Could Expose the People Behind a Global Extortion NetworkOct 5, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication4Global CMS Exploitation Wave Plants Webshells on Business Websites5Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path6Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards