Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

Exchange Server vulnerability could let a signed-in attacker read other users' email

Microsoft's October 2 updates fix an 8.8-rated Exchange Server flaw that could expose other users' mailboxes; Exchange Online is already fixed, on-prem servers are not.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1CVE-2026-96940 could let an authenticated attacker read other users' email and attachments in the same Exchange organization.
  • 2Microsoft fixed Exchange Online on its side; on-premises Exchange SE, 2019 and 2016 servers need the October 2 updates.
  • 3Microsoft rates exploitation more likely but listed the flaw as not exploited or publicly disclosed at release.

Video summary · 0:54

Watch: Exchange Server vulnerability could let a signed-in attacker read other users' email

The story in under a minute, with captions. Tap to play with sound.

Video summary · Voiced with a synthetic voice.

The news

Microsoft (MSFT) released security updates on October 2, 2026, for an Exchange Server vulnerability, CVE-2026-96940, that could let an authenticated attacker open other users' mailboxes in the same organization and read their email and attachments. Exchange Online is already fixed; on-premises servers are not.

Microsoft's advisory calls the bug an elevation of privilege flaw caused by weak authorization in Exchange Server. It carries a CVSS (Common Vulnerability Scoring System) score of 8.8 out of 10, which Microsoft rates Important. The attacker needs a valid account in the organization, but only low privileges, according to the CVSS rating Microsoft published.

Microsoft said it had already deployed a related service-side fix to Exchange Online, and that cloud customers do not need to take any action. The Hacker News reported that the flaw does not allow access across tenants, meaning one company's users could not reach another company's mail. Companies that run their own Exchange servers, including the on-premises half of hybrid setups, must install the update themselves.

The advisory listed the flaw as neither exploited nor publicly disclosed when it was released, but Microsoft's exploitability assessment is "Exploitation More Likely." The Hacker News, which described the release as out-of-band, outside Microsoft's usual monthly Patch Tuesday cycle, reported that the bug was found by Jan Mitchell, a Microsoft researcher.

Microsoft's support pages list four packages, each labeled version 2 of the October 2, 2026, security update: KB5129955 for Exchange Server Subscription Edition (SE) RTM, KB5129956 for Exchange Server 2019 Cumulative Update 15, KB5129957 for Exchange 2019 Cumulative Update 14, and KB5129958 for Exchange Server 2016 Cumulative Update 23. Each also lists eight other CVEs. Microsoft flags a known issue on all of them: published calendars in .ics format can return HTTP 500 errors to calendar apps.

The numbers

CVSS score
8.8 of 10 (Important)
Update release date
October 2, 2026
On-premises builds with a package
4 (SE RTM, 2019 CU15, 2019 CU14, 2016 CU23)
Other CVEs listed in the same packages
8
Last month of Exchange 2016/2019 updates (Microsoft, per BleepingComputer)
October 2026

Why CEOs should care

For CISOs, the threat model is simple. The attacker does not need admin rights, only a working account in the organization. A single phished or reused employee password could therefore become a route into the mailboxes of the CEO, the CFO or the general counsel, where deal terms, legal advice and board material sit. Install the update on every on-premises Exchange server, including hybrid servers that many teams forget once mail moves to the cloud, and review mailbox audit logs for unusual cross-mailbox access.

For IT leaders, check the build before you patch. Microsoft published packages for four specific builds, so a server sitting on an older cumulative update may not have a matching package. Test the .ics calendar known issue before a broad rollout if your organization publishes calendars to outside apps, and read the other known issues Microsoft lists for SE and Exchange 2016 hybrid setups.

For CFOs and boards, the bigger decision is the platform. Exchange Online customers received this fix without lifting a finger. On-premises customers carry the patching labor, the downtime and the risk of a missed update. If your company still runs Exchange 2016 or 2019, ask what the plan is for the months after October 2026 and what the migration will cost.

The bigger picture

The timing raises the stakes for older servers. BleepingComputer reported in July that Microsoft's Exchange team said there will be no further extension of the Exchange 2016/2019 Extended Security Update program, and that once October 2026 ends there will be no further updates for those versions, even for customers with a Period 2 ESU. Microsoft advised moving to Exchange Server SE, which supports in-place upgrades from Exchange 2019, or to Exchange Online. That makes the October 2 packages among the last fixes those servers can expect.

What’s next

Watch Microsoft's advisory for any change in its exploitation status, and for technical analysis from outside researchers, which often follows a Microsoft "Exploitation More Likely" rating and can shorten the time before attackers try a flaw. The Exchange 2016 and 2019 cutoff at the end of October 2026 is the next hard date for companies still running those versions, and Microsoft's next scheduled Patch Tuesday falls on October 13.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

MicrosoftExchange ServerEmail securityPatch management

Earlier coverage of Microsoft

All Microsoft coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.