Executive Summary
A critical vulnerability, CVE-2026-96940, has been identified in Microsoft Exchange Server, enabling authenticated attackers to escalate privileges and read the mailboxes of other users within the same organization. This flaw, rated CVSS 8.8 and assessed as "Exploitation More Likely" by Microsoft, affects on-premises Exchange deployments and has prompted an out-of-band security update. While there is currently no evidence of exploitation in the wild and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, the risk profile and attack surface make rapid remediation essential. Organizations running affected versions of Microsoft Exchange Server should prioritize patching and review access logs for anomalous activity.
Technical Information
CVE-2026-96940 is a privilege escalation vulnerability rooted in the authorization logic of Microsoft Exchange Server. Under specific conditions, an authenticated user can exploit this flaw to access mailboxes belonging to other users within the same on-premises organization. The attacker can read email messages and attachments, bypassing standard Role-Based Access Control (RBAC) and Active Directory permissions.
The vulnerability requires the attacker to possess valid credentials for any mailbox in the target organization. Once authenticated, the attacker can craft requests that exploit weak authorization checks, targeting other users’ mailboxes. The server erroneously authorizes these requests, granting unauthorized read access to emails and attachments. Notably, this flaw does not allow cross-tenant access, unauthenticated remote code execution, or write/delete/admin control over mailboxes.
The attack vector is network-based, requiring an authenticated session. The impact is a significant breach of confidentiality, as any mailbox in the organization could be compromised. Microsoft has not disclosed the exact API endpoint or triggering sequence to prevent immediate weaponization, but the vulnerability is considered highly exploitable due to the prevalence of credential theft via phishing, credential stuffing, or prior compromise.
Affected products include Microsoft Exchange Server Subscription Edition RTM, Microsoft Exchange Server 2019 Cumulative Update 15 (CU15), Microsoft Exchange Server 2019 Cumulative Update 14 (CU14), and Microsoft Exchange Server 2016 Cumulative Update 23 (CU23). Exchange Online (Microsoft 365) is not affected, as a service-side fix has already been deployed.
Detection and hunting for exploitation should focus on reviewing IIS logs (Client Access Server) and Information Store logs (Mailbox Server) for 30–60 days prior to patching. Security teams should look for EWS or MAPI/HTTP requests where the authenticated principal’s SMTP address does not match the target mailbox, excluding known service accounts, delegated access, and shared mailboxes. Behavioral indicators include cross-mailbox access (such as X-AnchorMailbox header or UPN mismatch), high-volume reads from a single account across multiple mailboxes, off-hours access to sensitive mailboxes (executive, legal, finance, HR), and new or unfamiliar OAuth application registrations or permission scopes. SIEM integration should map Exchange IIS log fields (cs-username, cs-uri-stem, cs-uri-query, sc-status) to rules targeting cross-mailbox access.
Immediate mitigation requires applying the out-of-band security update for your Exchange Server version, available via the Microsoft Update Catalog and the Microsoft Security Response Center Advisory for CVE-2026-96940. Verification of patch installation can be performed using the Exchange Management Shell with the command Get-ExchangeServer | Format-List Name, Edition, AdminDisplayVersion. Additional hardening steps include reviewing and minimizing RBAC assignments, enforcing MFA on all Exchange access paths (OWA, EWS, ActiveSync, PowerShell remoting), enabling and centralizing mailbox and admin audit logging, and restricting network access to Exchange roles to avoid direct internet exposure.
Exploitation in the Wild
As of the time of writing, there is no confirmed exploitation of CVE-2026-96940 in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and there are no public reports of active exploitation. However, Microsoft rates this vulnerability as "Exploitation More Likely," indicating that public proof-of-concept exploits and active attacks may emerge soon after patch release. The disclosure follows recent reports of the China-linked Warlock APT group exploiting Microsoft SharePoint vulnerabilities for ransomware deployment. While Warlock has not been linked to this Exchange flaw, their focus on Microsoft collaboration products increases the risk of rapid adoption.
APT Groups using this vulnerability
There is currently no direct attribution of CVE-2026-96940 exploitation to any Advanced Persistent Threat (APT) group. However, the China-linked Warlock APT group has demonstrated a pattern of targeting Microsoft collaboration products, including recent campaigns against SharePoint. Their tactics, techniques, and procedures (TTPs) suggest a high likelihood of pivoting to exploit this Exchange vulnerability, especially given the potential for data exfiltration and ransomware deployment. Organizations in Portuguese- and Spanish-speaking countries, particularly in Latin America, have been targeted by Warlock in the past.
Affected Product Versions
The following Microsoft Exchange Server versions are affected by CVE-2026-96940: Microsoft Exchange Server Subscription Edition RTM, Microsoft Exchange Server 2019 Cumulative Update 15 (CU15), Microsoft Exchange Server 2019 Cumulative Update 14 (CU14), and Microsoft Exchange Server 2016 Cumulative Update 23 (CU23). Exchange Online (Microsoft 365) is not affected, as a service-side fix has already been deployed.
Workaround and Mitigation
Immediate action is required to mitigate this vulnerability. Organizations should apply the out-of-band security update for their Exchange Server version, available from the Microsoft Update Catalog and the Microsoft Security Response Center Advisory for CVE-2026-96940. After patching, verify installation using the Exchange Management Shell. Additional mitigation steps include reviewing and minimizing RBAC assignments, enforcing MFA on all Exchange access paths, enabling and centralizing mailbox and admin audit logging, and restricting network access to Exchange roles to avoid direct internet exposure.
Indicators of Compromise
The following caveat applies: Indicators of Compromise (IOCs) are point-in-time and should be validated before enforcement. No public indicators of compromise were available at the time of writing.
References
The Hacker News: Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes, The CyberSec Guru: CVE-2026-96940 Microsoft Exchange Vulnerability, Microsoft Security Response Center Advisory for CVE-2026-96940, Symantec Warlock APT Research, Shadowserver: Exchange Vulnerability Exposure
Rescana is here for you
Rescana provides a comprehensive Third-Party Risk Management (TPRM) platform, empowering organizations to continuously monitor, assess, and mitigate cyber risks across their supply chain and vendor ecosystem. Our platform delivers actionable intelligence and automated workflows to help you stay ahead of emerging threats. We are happy to answer questions at info@rescana.com.



