Microsoft has released out-of-band security updates to address a high-severity vulnerability in Microsoft Exchange Server that could allow authenticated attackers to escalate their privileges under certain conditions.
Tracked as CVE-2026-96940, the vulnerability carries a CVSS score of 8.8. Microsoft described the issue as a weak authorization flaw that could allow an authenticated attacker to elevate privileges over a network.
According to Microsoft, successful exploitation could give an attacker unauthorized access to other users’ mailboxes within the same organization, allowing them to read email messages and attachments. The vulnerability does not, however, allow attackers to access mailboxes across different tenants.
Microsoft has already deployed a related service-side fix for Exchange Online, meaning customers using the cloud-based service do not need to take any action. Organizations running affected on-premises versions of Exchange Server are advised to install the available security updates as soon as possible.
The affected products include Microsoft Exchange Server Subscription Edition RTM, Exchange Server 2016 Cumulative Update 23, Exchange Server 2019 Cumulative Update 15, and Exchange Server 2019 Cumulative Update 14.
Microsoft credited security researcher Jan Mitchell with discovering and reporting the vulnerability. While there is currently no evidence that CVE-2026-96940 has been exploited in the wild, Microsoft has classified its exploitability as “Exploitation More Likely,” increasing the urgency for organizations to apply the patches.
The disclosure comes shortly after Broadcom-owned Symantec warned that the China-linked Warlock threat actor has been exploiting multiple Microsoft SharePoint vulnerabilities to deploy its namesake ransomware against organizations in Portuguese- and Spanish-speaking countries.



