The images in this article were generated with artificial intelligence. How we publish
Microsoft published an off-schedule security update on October 2, 2026 to correct a high-severity vulnerability in Microsoft Exchange Server, registered as CVE-2026-96940 and qualified with 8.8 on the CVSS scale. According to the official notice, the failure is taken advantage of by a weak authorization problem that allows an authenticated attacker to scale privileges on the network and access other users' mailboxes within the same organization; Microsoft clarifies that it does not allow access between tenants (cross- tenant). Exchange Online already received a correction on the service side, but on-premises that run affected versions must install published updates to close the gap.
Technically, Microsoft describes vulnerability as an authorization failure: in general terms that means that the logic that verifies whether a user has the right to see or manipulate resources (in this case, mailboxes and their content) can be mocked when the attacker already has valid credentials. The confirmed vector is an authenticated actor so, according to Microsoft, the operation requires some kind of prior access (e.g. committed credentials, legitimate abused accounts or stolen tokens). With that access, an attacker can list or open foreign mailboxes and read messages and attachments; Microsoft expressly indicates that there is no public evidence of active exploitation so far, but has assessed the possibility of exploitation as "Exploitation More Likely."

The affected on-premises issues identified by Microsoft include: Microsoft Exchange Server Subscription Edition RTM, Microsoft Exchange Server 2016 Cumulative Update 23, and Microsoft Exchange Server 2019 Cumulative Updates 14 and 15. Exchange Online received an arrangement on the service side, so cloud customers do not need additional action unless they check their settings. Microsoft accredited researcher Jan Mitchell for the discovery and report responsible for the failure.
Who does this really affect? Confirmed: organizations that maintain non-patched Exchange on-premises servers and that use any of the above versions are exposed. Also at greater risk are the environments where Exchange interfaces are accessible from the Internet or where accounts with weak passwords or without multifactor authentication exist. Reasonable estimate: attackers who have already obtained credentials by phishing, filtered credentials or prior exploitation of another vulnerability can channel such access to exploit CVE-2026-6940 and obtain lateral visibility over internal communications.
The concrete, confirmed and potential consequences must be separated. Confirmed fact: the operation allows you to read emails and attachments of other mailboxes within the organization. Estimates based on patterns observed in previous incidents: access to e-mails can facilitate business email-related fraud, intellectual property theft, extortion intelligence collection and preparation of subsequent attacks such as Ransomware distribution or lateral movement to critical systems. There is, for now, no public evidence that actors have exploited this failure for mass campaigns, but Microsoft's label on the likelihood of exploitation suggests that the operational risk is high and should be treated with priority.
Urgent and concrete actions to be taken by security managers and teams: 1) Apply the patches published by Microsoft immediately on all affected Exchange on-premises servers. Microsoft keeps the vulnerability guide and update packages on its portal; see the specific vulnerability entry to download and follow instructions: Microsoft Security Response Center - CVE-2026-96940. 2) Check that Exchange Online shows the expected mitigation status(the cloud correction was already applied by Microsoft, but it is appropriate to review records and configurations). For information on the official CVE register, see the NVD tab: NVD - CVE-2026-96940.
Recommended additional operational actions (provided that they do not contradict official Microsoft guides): strengthen authentication (force MFA in all accounts with exchange access), review and rotate service account credentials, restrict external access to exchange ports and interfaces where possible and apply network-based access controls (VPN, control lists). If the patch cannot be applied immediately, assess temporary measures such as limiting external access to the mail service, tightening firewall rules and increasing monitoring of authentication events and access to mailboxes.

Detection and response: look for signs of unauthorized access to mailboxes - for example, early session from unusual locations, sudden changes in forwarding or delegation rules (autoforwarding), mass searches within mailboxes and unusual downloads of attachments. Check the Exchange audit log and identity records (Identity Protection, ICES). If possible exploitation is detected, treat the incident as serious: isolate the affected server, collect evidence (logs, memory-turned if applicable), restore committed credentials, and activate incident response processes and legal and regulatory notification as appropriate.
Threat context: This disclosure comes at a time when threat actors have shown a tendency to channel failures on collaboration and mail platforms to get access and deploy harmful charges. Days before, security providers reported offensive activities aimed at collaborative platforms that led to the distribution of ransomware in certain regions; while there is no public link between these incidents and CVE-2026-96940, the operating pattern (exploiting gaps in collaborative infrastructure for benefits) reinforces the importance of rapidly patching.
In summary: vulnerability allows an authenticated attacker to read foreign mailboxes and Microsoft considers the exploitation "more likely" and therefore organizations with Exchange on-premises should prioritize the application of patches and conduct immediate audits of access to mailboxes and users with privileges. Exchange Online was already mitigated by Microsoft, but the responsibility lies with on-premises operators to prevent a committed credential from becoming a gateway to internal mail and a base for major incidents.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...