NCSC warns of mailbox access via Exchange server
A vulnerability could give users with limited privileges greater access to local Exchange mailboxes.
The National Cyber Security Centre is warning organisations that manage their own Microsoft Exchange server about a vulnerability that could expose mailboxes. Microsoft released a security update on 2 October as an expedited measure.
The vulnerability is registered as CVE-2026-96940. According to the US National Vulnerability Database, it involves weak authorisation that could allow an attacker who already has an account to gain higher privileges over the network.
The vulnerability affects specific versions of Exchange Server 2016, Exchange Server 2019 and Exchange Server Subscription Edition. These are local servers managed by organisations themselves. Microsoft says Exchange Online customers are protected against the vulnerability and do not need to take separate action on this issue.
According to security analyses, an attacker with a low-privilege Exchange account could try to gain access to other users’ mailboxes within the same organisation. This could allow confidential emails and attachments to be read. The NVD rates the vulnerability as severe and gives it a CVSS score of 8.8.
Microsoft released the update as the second version of the security updates for September 2026. The company says the addition covering CVE-2026-96940 was published earlier than planned and advises administrators to install the update as soon as possible.
The situation is more complicated for Exchange 2016 and 2019. Those versions are outside regular support. Only organisations participating in the second Extended Security Updates programme receive the new security updates for these versions. According to Microsoft, other organisations should move to Exchange Server Subscription Edition.
Microsoft says it is not aware of active exploitation of this specific vulnerability. That does not mean the risk has disappeared: once technical details become widely available, attackers may try to find vulnerable servers. Administrators should therefore not only install the update, but also check that this was done correctly and review the logs for unusual activity in mailboxes.
Fact-check Approved · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The technical core has been confirmed by Microsoft, the NVD and a second national cyber centre. The text distinguishes between a proven privilege escalation and its active exploitation, which has not yet been demonstrated.
- confirmed CVE-2026-96940 concerns an authorisation problem that could allow an attacker to raise their privileges. — The NVD and Microsoft describe the vulnerability as privilege escalation caused by weak authorisation. source
- confirmed Microsoft released a second version of the Exchange security updates on 2 October. — The Microsoft Exchange Team mentions the V2 release and its publication date. source
- confirmed According to Microsoft, Exchange Online is not affected. — Microsoft writes that Exchange Online customers are already protected. source
- confirmed The CVSS score is 8.8. — The NVD lists the CVSS 3.1 score of 8.8 supplied by Microsoft. source
- confirmed Microsoft says it is not aware of active exploitation. — This is stated in the Microsoft Exchange Team’s explanation. source
Editor's note
The vulnerability, affected versions and patch have been confirmed. Microsoft reports no knowledge of active exploitation; the possible mailbox access follows from the privilege escalation and security analyses.Sources
- Released: September 2026 V2 Exchange Server Security Updates — Microsoft Exchange Team
- CVE-2026-96940 — National Vulnerability Database
- Microsoft security advisory AV26-1001 — Canadian Centre for Cyber Security