Exchange flaw CVE-2026-96940 lets users read colleagues' mail
CVE-2026-96940, a CVSS 8.8 weak-authorization flaw in on-prem Exchange, lets an authenticated user read other mailboxes in the same org. Fix ships in the September V2 security updates.
Microsoft has patched CVE-2026-96940, a weak-authorization flaw (CVSS 8.8) in on-premises Exchange Server that lets an authenticated user read other users' mailboxes — messages and attachments — within the same organization. The fix ships as a reissued "V2" build of the September 2026 Exchange security updates. Microsoft's advisory is in the MSRC update guide; the NVD record is here.
What the bug does
The flaw is an improper authorization check: a user who can already authenticate to Exchange can access mailboxes they shouldn't, reading mail and attachments without the mailbox owner's interaction. Microsoft scopes the access to within a single organization — it does not cross tenant boundaries. Rated "Exploitation More Likely" on Microsoft's exploitability index, it needs low privileges and no user interaction, which is why the 8.8 lands in the high band rather than critical.
What's affected
On-premises Exchange only. Exchange Online was fixed service-side by Microsoft and needs no customer action. Per CERT-FR's parallel advisory CERTFR-2026-AVI-1258, the fixed builds are:
- Exchange Server 2016 CU23 — 15.01.2507.075 and later
- Exchange Server 2019 CU14 — 15.02.1544.048 and later
- Exchange Server 2019 CU15 — 15.02.1748.053 and later
- Exchange Server Subscription Edition RTM — 15.02.2562.053 and later
The important wrinkle: this is a V2 reissue of the September 2026 updates. If you installed the original September security update, you are not covered — you must apply the V2 build. Microsoft reissued the package specifically to carry this fix.
Exploitation status
Microsoft says the vulnerability was found internally and that it is not aware of active exploitation at disclosure. There is no public proof-of-concept and no in-the-wild reporting from GreyNoise, a vendor advisory, or a named research team at this time. The "Exploitation More Likely" rating is a forecast, not an observation — treat it as a reason to patch promptly, not as evidence of ongoing attacks.
Action checklist
- Inventory on-prem Exchange. Anything on 2016, 2019, or Subscription Edition is in scope; Exchange Online is not.
- Confirm whether you are on the V2 September build, not the original September update. Check the build number against the list above — the original September patch does not fix this.
- Apply the V2 security update, then re-run
Get-ExchangeServerAccessTokenStatus/ your normal post-update health checks and HealthChecker. - Review mailbox audit logs for anomalous cross-user access while you schedule the patch. The flaw leaves access inside normal Exchange auth paths, so log review is the only pre-patch detection you have.
- Keep OWA and the Exchange management surfaces off the public internet regardless.
Context
On-prem Exchange has been a standing target since ProxyLogon and ProxyShell, and Microsoft's current servicing model — folding hotfixes into cumulative updates and, as here, reissuing a month's package as a V2 — means "we patched in September" is no longer a complete answer. The failure mode this time is mundane by Exchange standards: not RCE, but a broken authorization check that turns any mailbox-holding account into a window onto its colleagues' mail. For regulated inboxes that is a reportable-incident risk on its own, exploit code or not.