← All security news

Microsoft Patches Exchange Flaw That Exposes Colleagues' Mailboxes

An envelope icon with a cracked lock on its flap next to a row of other mailbox icons, representing an Exchange Server flaw that lets one logged-in user read a colleague's mailbox

Microsoft has shipped an out-of-band security update for Exchange Server after finding a flaw, tracked as CVE-2026-96940, that lets someone who already has a valid mailbox account read other employees' email and attachments inside the same organisation. Microsoft rates the bug 8.8 out of 10 and tags it "exploitation more likely," though it says its own engineers found the issue internally and are not aware of anyone using it yet. The weakness sits in how Exchange checks who is allowed to open which mailbox; get past that check and a logged-in attacker can browse messages that were never meant for them, with no extra action needed from the victim.

The affected versions are all on-premises installs: Exchange Server Subscription Edition, Exchange Server 2019 (Cumulative Updates 14 and 15), and Exchange Server 2016 (Cumulative Update 23). Exchange Online customers were already covered by a service-side fix before the public advisory went out — in fact Microsoft later confirmed the fix shipped ahead of its own documentation, which is why some admins only heard about it after the cloud side was already patched. The bug does not reach across tenants or into a different company's Microsoft 365 setup; the risk is one colleague reading another colleague's mail inside the same business.

What this means for your business

If your business still runs Exchange on its own servers, rather than fully on Microsoft 365, ask whoever manages it this week whether the September 2026 "v2" security update has been installed — including on any machine that only runs the Exchange Management Tools, which Microsoft specifically flagged as needing the update too for compatibility. This is usually an IT provider or an in-house admin, not your website developer, so it is worth a direct message rather than assuming routine patching already caught it.

Because the attacker needs a working company login first, this is also a reminder that account hygiene inside your own organisation matters as much as the perimeter: unique passwords, multi-factor authentication, and promptly deactivating accounts for staff who have left all reduce who could ever attempt this. If your business runs a hybrid setup — some mailboxes on Microsoft 365, others on an on-premises Exchange server kept for compatibility — confirm both sides were checked, since it is easy to assume a cloud migration covered everything when a legacy server is still quietly handling mail.

Questions about your own setup? contact@techleetsolutions.com
Sources: Microsoft Security Response Center, Help Net Security, The Hacker News