Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Microsoft Exchange Vulnerability Could Leak Confidential Organizational Info

Threat actors could first obtain credentials through phishing attacks or by purchasing stolen login details from underground online markets.


Microsoft has issued an emergency security update to fix a vulnerability in Exchange Server that could expose confidential organizational communications. The flaw, tracked as CVE-2026-96940, has received a CVSS severity score of 8.8 out of 10.

Reported by TechRadar, the vulnerability could allow attackers who already have valid login credentials to increase their privileges within Exchange and access mailboxes belonging to other users. Microsoft released the fix on October 2, ahead of its originally intended schedule.

About the flaw

The security issue stems from a weakness in authorization controls, which determine what information a user can access. By exploiting the flaw over a network, an authenticated attacker could gain permissions beyond those assigned to their account.

Threat actors could first obtain credentials through phishing attacks or by purchasing stolen login details from underground online markets. Once inside an organization’s Exchange environment, they could exploit the vulnerability to read emails and attachments belonging to other employees.

However, the flaw does not provide unrestricted access across different customer environments, known as tenants. It also does not directly grant administrator-level or SYSTEM-level privileges on the underlying Windows server.

What happens in case of successful exploitation?

Successful exploitation could expose sensitive business information, including financial records, invoices, contracts, customer correspondence, internal discussions, and confidential documents.

Attackers could use the stolen information to support further cyberattacks. For example, they might impersonate company employees, send convincing fraudulent emails, or conduct business email compromise (BEC) scams to trick organizations into transferring money or disclosing additional information.

The vulnerability is particularly problematic because an ordinary employee’s compromised account could potentially provide an entry point for accessing information held in other employees’ mailboxes.

Affected products

The vulnerability affects the following on-premises products:

  • Microsoft Exchange Server Subscription Edition RTM
  • Microsoft Exchange Server 2016 Cumulative Update 23
  • Microsoft Exchange Server 2019 Cumulative Updates 14 and 15

Microsoft has confirmed that Exchange Online customers are protected by a server-side fix. Organizations running affected on-premises installations should install the appropriate security updates promptly.

Exchange Server 2016 and 2019 have reached the end of their standard support lifecycle. Eligible organizations must be enrolled in Microsoft’s Extended Security Update programme to receive the relevant updates for these versions. Microsoft recommends that organizations without the required coverage migrate to Exchange Server Subscription Edition.

Microsoft’s response 

Microsoft reported no evidence that the vulnerability was being actively exploited at the time of the report. However, the company assessed that exploitation was more likely, making timely patching important.

Administrators should run Microsoft’s Exchange Server Health Checker after installing the update to verify successful deployment and identify any additional actions required.

Share it:

Cyber Security

Microsoft

Microsoft Exchange

Organization Security

Severe Flaw