What Happened
Microsoft disclosed Exchange vulnerability CVE-2026-96940 on October 2. The Hacker News reports a weak authorization flaw with a CVSS score of 8.8. An authenticated attacker elevates privileges over the network and reads other users’ mailboxes in the same organization. The flaw does not allow cross-tenant access.
Affected versions are Exchange Server Subscription Edition RTM, Exchange Server 2016 CU23, and Exchange Server 2019 CU14 and CU15. Microsoft fixed Exchange Online on the service side, so cloud customers need no action. On-premises customers must install the updates. Microsoft rates exploitation as more likely, and no attacks are reported yet. Microsoft researcher Jan Mitchell reported the flaw.
Why This Matters for Canadian Organizations
Many Canadian school boards, municipalities, hospitals, and mid-sized firms still run Exchange on their own servers. Those organizations carry the full patching burden. A low-privilege account is enough to start. Phished staff credentials, a contractor login, or a reused password gives an attacker a path to executive and finance mailboxes.
Mailbox access exposes contracts, health information, employee records, and password reset links. Under PIPEDA, unauthorized access to personal information in email counts as a breach of security safeguards. You must assess the risk of significant harm and keep records. Our earlier coverage of CVE-2026-42897 showed how fast attackers move on Exchange once details circulate.
What to Do
Inventory every on-premises Exchange server and confirm its cumulative update level. Install the October updates on 2016 CU23, 2019 CU14 and CU15, and Subscription Edition. Enforce multi-factor authentication to shrink the pool of usable accounts. Audit mailbox access logs for one account reading another user’s data. Review our TechTalk section and daily briefs for related Exchange coverage.






