One phished login could read any inbox on on-prem Exchange — install the reissued update

By George Bailey   Published: 10/06/26   5 min read

If you still run Exchange on your own servers, one phished employee login may be all it takes to read someone else’s mail. Microsoft shipped an out-of-band fix on Friday, October 2, for a flaw that lets any authenticated user open other mailboxes in the same organization, attachments included. Exchange Online is already fixed. Your on-prem servers are not, and that includes any that already installed September’s update.

One ordinary login, and the CFO’s inbox is readable. Exchange Online is fixed. Your server is not.

What happened

Microsoft published CVE-2026-96940 on October 2, 2026, outside the normal Patch Tuesday cycle. It describes the bug as “weak authorization in Microsoft Exchange Server” that lets an authenticated attacker elevate privileges over a network. In practice, an attacker with any mailbox account in the organization can gain access to other users’ mailboxes and read their messages and attachments. Microsoft says it does not cross tenant boundaries. The score is CVSS 8.8.

The fix comes as a reissued package, the “September 2026 V2” Security Updates. The Exchange Server team says the only difference from the original September release is the addition of CVE-2026-96940. It also says this update “was published ahead of its intended schedule” and asks customers to apply it at the earliest opportunity. Microsoft found the flaw internally, credits researcher Jan Mitchell, and says it is not aware of active exploitation. It still rates the bug “Exploitation More Likely.”

Microsoft pushed a related service-side fix to Exchange Online late last week, so cloud-only tenants have nothing to do. Hybrid organizations still have to patch the Exchange servers they keep for management.

Why it matters

Mailbox-to-mailbox access is what business email compromise crews want: invoices, legal threads, password resets, board decks. The precondition is only “has an account.” That is any phished user, any sprayed password, any contractor account nobody disabled. Microsoft has not said which Exchange component is involved, so do not count on a WAF rule or a disabled protocol to cover it. The update is the control.

There is a second clock for Exchange 2016 and 2019. Both are out of support. Only organizations enrolled in the Period 2 Extended Security Update program can download these fixes, and Microsoft says that program covers updates released through the end of October 2026. If you are on 2016 or 2019 without ESU, there is no package for you. The way out is Exchange Server Subscription Edition.

What to do first

Forward this

If you own email, or you own the budget for it: any employee account on our on-prem Exchange servers can currently be used to read other people’s mailboxes until we install Microsoft’s October 2 update (“September 2026 V2”). Exchange Online is already fixed. On-prem and hybrid management servers need the update this week. If we are on Exchange 2016 or 2019 without the extended-support contract, we cannot get this fix at all, and moving to Exchange SE needs a date.

Details

Hunt / verify

Slack paste: On-prem Exchange: install the September 2026 V2 Security Update (released Oct 2) on every Exchange server and Management Tools host. Any authenticated user can read other mailboxes until then. Original Sept SU does not include the fix. Exchange Online already fixed. 2016/2019 need Period 2 ESU. CVE-2026-96940.

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.