Security1 publisher2 min readPublished
Out-of-band Exchange Server patch closes a flaw that exposes colleagues' mail to signed-in attackers
Microsoft issued an out-of-band Exchange Server fix for CVE-2026-96940, a bug letting signed-in attackers read colleagues' mail and attachments. The company expects the flaw to be consistently exploitable, so on-premises admins have good reason to install it ahead of the next maintenance window.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Microsoft says the flaw does not allow access across tenant boundaries, so exposure stays inside a single organization.
- Microsoft found the bug internally and says it is not aware of any active exploitation.
- A related service-side fix reached Exchange Online late last week, at first without a KB article explaining what it changed.
- Microsoft later said the update had gone out ahead of its intended schedule, but did not say why.
- Packages cover Exchange Server Subscription RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure On any unpatched server, one compromised or malicious account inside the organization is enough to open other users' mail and attachments.
- decision A vendor forecast of consistent exploitation, in a bug class attackers have used before, argues for taking the out-of-band patch now instead of holding it for the next scheduled window.
- constraint Servers on cumulative updates outside the four covered builds have to reach a covered build before this fix can go on, which lengthens the path to being patched.
- cost The change window grows to include every admin workstation running the Exchange Management Tools, beyond the mail servers themselves.
Exploitation requires one working login. The attacker has to be authenticated and inside the same organization as the target mailboxes [2]. Anyone holding a single valid account on an unpatched server meets that condition. An outsider with no credentials does not [13]. The flaw is rated high-severity [1].
Microsoft also points to history. It notes that this type of vulnerability has been exploited in the past, and it advises admins to update sooner rather than later [5][6]. No exploitation of this CVE is known, so there is no actor or campaign to tie it to yet [15]. The Exchange Server Team recommended that customers review the deployment guidance and install the September 2026 v2 update as soon as they can [10].
Exchange Online tenants got their fix on Microsoft's side of the service [7]. Their confusion was over what had changed, and the team's account of the rollout covers only its timing [8]. On-premises admins have to install the security update themselves [6].
The release has packages for four builds [12]. A server on any other cumulative update has nothing to install from it [14]. The install list also goes beyond the mail servers. "Our recommendation is to install SUs on all Exchange Servers and all servers and workstations running the Exchange Management Tools to ensure compatibility between management tools clients and servers," the team said [11].
What to watch
- Any Microsoft revision to the 'not aware of active exploitation' status for CVE-2026-96940.
- A public proof-of-concept or patch-diff writeup for CVE-2026-96940.
- An explanation from Microsoft of why the update was published ahead of its intended schedule.