MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-05 · via Help Net Security

Microsoft releases emergency patch for Exchange Server vulnerability allowing unauthorized email access

Image via Help Net Security
Image via Help Net Security

Microsoft deployed an out-of-band security update to address a high-severity flaw in Exchange Server that could permit authenticated users to access emails and attachments belonging to other organization members. The vulnerability was discovered internally with no current evidence of active exploitation, though Microsoft believes it poses a consistent exploitation risk. The update is available for multiple Exchange Server versions, with administrators urged to apply it immediately.

Expanded Detail

Microsoft discovered this flaw through internal testing rather than external reports, and the company acknowledges the vulnerability mirrors patterns seen in previous exploits targeting similar systems. The patch covers multiple Exchange Server versions, spanning from older 2016 installations through the latest subscription releases, indicating the flaw affected a broad range of deployments across different upgrade cycles.

The rollout process itself deviated from standard procedures, with Microsoft deploying a related fix to its cloud-based Exchange Online service before completing documentation and advance notification to administrators. This unusual sequencing created confusion among IT teams managing both on-premises and cloud infrastructure.

Context

Organizations running Exchange Server on-premises could face significant operational risk if patches remain undeployed, as the vulnerability permits employees with basic system access to view colleagues' confidential communications and sensitive attachments. The threat may be particularly acute for enterprises handling regulated information, competitive intelligence, or personal data. However, since exploitation requires authenticated user access within a single organization, the scope differs from vulnerabilities exposing data across multiple companies or the public internet.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at Help Net Security →
Related stories
CISA Releases Critical Advisory on Physical Access Control System Vulnerabilities · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940).” Browse more stories.