Microsoft has released an out-of-band security update for CVE-2026-96940, a high-severity Exchange Server vulnerability that may allow an authenticated attacker to read another user’s email and attachments within the same organization. The reported scope does not cross tenant boundaries.

Microsoft says it is not aware of active exploitation, but advises administrators to deploy the update promptly because this class of issue has been exploited historically. The update applies to supported on-premises Exchange Server Subscription Edition RTM, Exchange Server 2019 cumulative updates 14 and 15, and Exchange Server 2016 cumulative update 23.

Exchange administrators should review Microsoft’s deployment guidance, update every Exchange server, and keep Exchange Management Tools clients compatible with the server versions. As with other Exchange servicing events, validate backup and recovery coverage before rollout, then confirm the installed security-update level across the fleet.

This is an authentication-required issue, but that does not make it low priority. Organizations with broad internal access, shared administrative boundaries, or exposed credential risk should treat the update as a near-term remediation item.

Source: Help Net Security; Microsoft Exchange Team.

By Allan