search

LEMON BLOG

Microsoft Exchange Server Vulnerability Could Allow Attackers To Access Other Users’ Mailboxes

Microsoft has released an urgent security update addressing a high-severity vulnerability affecting several versions of Microsoft Exchange Server. Tracked as CVE-2026-96940, the flaw could allow an authenticated attacker to elevate privileges and access mailboxes belonging to other users within the same environment. Because Exchange servers often contain sensitive corporate email and attachments, the vulnerability represents a significant risk for organisations running on-premises deployments.

The issue carries a CVSS 3.1 base score of 8.8 out of 10 and has been rated High in severity. Microsoft has not reported active exploitation in the wild at the time of disclosure, but it has classified the vulnerability as "Exploitation More Likely". This makes prompt patching particularly important for affected organisations.

CVE-2026-96940 Involves Weak Authorisation Controls

The vulnerability is linked to weak authorisation controls within Microsoft Exchange Server. An authenticated attacker could potentially abuse the flaw over the network to gain additional privileges beyond those normally granted to the compromised account. This could allow access to email messages and attachments stored in other users' mailboxes.

Unlike many attacks that require a victim to open a malicious file or click a specially crafted link, exploitation of CVE-2026-96940 does not require user interaction. That reduces the number of steps an attacker needs once valid access to an Exchange environment has already been obtained. The reported mailbox access, however, does not extend across separate tenant boundaries.

Why Mailbox Access Is A Serious Concern

Corporate mailboxes often contain a large amount of sensitive information, including internal discussions, financial records, business documents, customer information and confidential attachments. If an attacker is able to expand access from one compromised account to other users' mailboxes, the potential impact can quickly become much more serious.

The vulnerability is particularly concerning for organisations that rely heavily on Exchange Server for internal communication. Even when an attacker does not obtain full administrative control of the server, access to additional mailboxes may expose information that can support further attacks. This could include credential theft, social engineering or the collection of sensitive business intelligence.

Affected Microsoft Exchange Server Versions

CVE-2026-96940 affects several supported Microsoft Exchange Server releases. Organisations using the following versions should verify that the latest security updates have been installed:

Exchange Online is also affected by the underlying issue. However, Microsoft has already deployed a related service-side fix for Exchange Online, meaning customers using the cloud-hosted service do not need to take additional action to receive the protection.

Microsoft Says Exploitation Is More Likely

At the time the vulnerability was disclosed, Microsoft had not observed active exploitation in the wild. Despite this, the company rated the likelihood of exploitation as "Exploitation More Likely". This classification reflects the potential impact of a successful attack against an Exchange Server environment.

For organisations running on-premises Exchange, this should be treated as a reason to patch quickly rather than waiting for evidence of active attacks. Once technical details become more widely available, vulnerabilities affecting enterprise email systems can attract significant attention from threat actors. Reducing the time between disclosure and patch deployment therefore remains an important part of risk management.

September 2026 V2 Update Adds Protection

Microsoft has released a September 2026 V2 update that adds protection against CVE-2026-96940 to the original September 2026 security updates. Organisations that installed the earlier September release should not automatically assume that their servers are already protected against this particular vulnerability. Administrators should review the newer packages and confirm that the V2 update has been applied.

This distinction is important because the vulnerability fix was added after the original September update. A server may therefore appear fully patched based on the earlier release while still missing the newer protection. Exchange administrators should verify the installed build number rather than relying solely on the date of the last update.

Expected Build Numbers After Updating

After installing the latest security updates, the expected Microsoft Exchange Server build numbers are:

Administrators can use these build numbers to confirm whether the correct update has been applied. Verifying the installed version is especially useful in environments where multiple Exchange servers are operating or where patch deployment is managed across different maintenance windows.

How To Check The Exchange Server Build Number

Exchange administrators can verify the installed build by opening the Exchange Management Shell as an administrator. The following command can be used to display the server name, edition and installed Exchange version:

Get-ExchangeServer | Format-List Name, Edition, AdminDisplayVersion

The reported version should then be compared against the latest expected build for the relevant Exchange release. If the number is lower than the version associated with the V2 security update, the server should be reviewed and patched accordingly.

Organisations Should Prioritise On-Premises Exchange Servers

The immediate priority is for organisations running Exchange Server on-premises because those systems require administrators to apply the update themselves. Exchange Online users benefit from Microsoft's service-side remediation and do not need to manually deploy the fix. This makes patch management especially important for organisations that maintain their own Exchange infrastructure.

Administrators should also review whether all affected servers have been updated consistently. In larger environments, a single unpatched Exchange server can still represent a security weakness even if the rest of the deployment has already been updated. Maintaining accurate patch and build inventories can help avoid this type of oversight.

Final Thoughts

CVE-2026-96940 is a high-severity Microsoft Exchange Server vulnerability that could allow authenticated attackers to elevate privileges and access other users' mailboxes. With a CVSS score of 8.8 and Microsoft classifying exploitation as more likely, organisations running affected on-premises Exchange versions should treat the update as a priority.

Administrators should also note that the protection was added through the September 2026 V2 update, meaning earlier September patches may not be sufficient on their own. Verifying the installed build number and applying the latest security package is the most reliable way to ensure affected Exchange servers are properly protected.

Malaysia Consolidates Driving Licences, Passports,...
Ryt Bank Adds Apple Pay Support For Its Visa Debit...

Related Posts

 

Comments 0

Loading latest comments...
Wednesday, 07 October 2026

Captcha Image

LEMON VIDEO CHANNELS

Step into a world where web design & development, gaming & retro gaming, and guitar covers & shredding collide! Whether you're looking for expert web development insights, nostalgic arcade action, or electrifying guitar solos, this is the place for you. Now also featuring content on TikTok, we’re bringing creativity, music, and tech straight to your screen. Subscribe and join the ride—because the future is bold, fun, and full of possibilities!

My TikTok Video Collection