Skip to content
ThreatCluster

Microsoft Exchange Server Vulnerability CVE-2026-96940 Disclosed

First seen 4 Oct 2026, 04:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 06:06 UTC
  • •CVE-2026-96940 allows privilege escalation in Microsoft Exchange Server.
  • •Authenticated attackers can access other users' mailboxes within the same organization.
  • •On-premises administrators must install September V2 patches to mitigate this vulnerability.

On October 2, 2026, Microsoft disclosed CVE-2026-96940, a privilege escalation vulnerability in Microsoft Exchange Server. This flaw allows authenticated attackers to gain unauthorized access to other users' mailboxes within the same organization. The vulnerability has a CVSS score of 8.8, categorizing it as high severity. Microsoft has already deployed a fix for Exchange Online, and on-premises administrators are advised to install the September V2 patches to mitigate the risk. The vulnerability does not allow access across tenant boundaries. The patch is crucial as it builds on previous updates addressing remote code execution and mailbox takeover risks. Administrators should verify the installation of the V2 patches to ensure protection against this flaw.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-02
CVE-2026-96940 published
Microsoft disclosed a privilege escalation vulnerability in Exchange Server affecting authenticated users.
Api.Msrc.Microsoft
2026-10-03
September V2 patches released
Microsoft's September V2 updates include a fix for CVE-2026-96940, addressing mailbox access risks.
Feeds.4Sysops

More articles in this cluster (2)

Following this threat?

Track CVE-2026-96940 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of Exchange Server are affected?
The vulnerability affects on-premises Microsoft Exchange Server products that have not applied the September V2 patches.
What should I do if I'm using Exchange Online?
No action is required for Exchange Online customers as Microsoft has already deployed a fix.
How urgent is it to apply the September V2 patches?
It is critical for on-premises administrators to apply the patches promptly to prevent unauthorized mailbox access.