- Microsoft said CVE-2026-96940 is rated 8.8 on CVSS and could allow authenticated attackers to elevate privileges over a network.
- Microsoft said an attacker could access other users’ mailboxes and read messages and attachments within the same organization.
- Microsoft said there is no evidence the flaw has been weaponized in the wild.
Microsoft released out-of-band security updates for CVE-2026-96940, a high-severity flaw in on-premises Microsoft Exchange Server that could let an authenticated attacker elevate privileges over a network.
Microsoft said an attacker could use the flaw to access other users’ mailboxes and read email messages and attachments within the same organization. The flaw does not allow cross-tenant access, and Microsoft said there is no evidence it has been weaponized in the wild.
Microsoft said the vulnerability allows attackers with administrator access to an on-premises server to escalate privileges in the connected cloud environment, potentially compromising the entire domain.
On this page
Administrative access is required before exploitation
CISA said exploitation is possible only after an attacker establishes administrative access on the on-premises Exchange server. Microsoft’s assessment nevertheless rates exploitation as “Exploitation More Likely.”
CISA ordered checks, disconnections and Exchange updates
CISA required agencies to run Microsoft’s Exchange Server Health Checker script, identify their current cumulative update levels and disconnect servers that were not eligible for the April 2025 hotfix updates, including end-of-life servers.
CISA’s Emergency Directive 25-02 applied to Federal Civilian Executive Branch agencies and required mitigation by 9:00 a.m. EDT on August 11. The agency also required reporting through a CISA-provided template by 5:00 p.m. EDT on August 11, 2025.
CISA said the vulnerability poses a grave risk to organizations operating Microsoft Exchange hybrid-joined configurations that have not yet followed the April 2025 patch guidance. According to Shadowserver, 29,098 Exchange servers were exposed as of Aug. 10, with the highest concentrations in the United States, Germany and Russia.
| Action | Requirement |
|---|---|
| Server inventory | Run Microsoft’s Health Checker script and identify the current cumulative update level. |
| Unsupported servers | Disconnect servers not eligible for the April 2025 hotfix updates. |
| Updates | Install Exchange 2019 CU14 or CU15 and apply the April 2025 hotfix updates to hybrid Exchange servers. |
| Hybrid identity | Replace the legacy shared service principal with a dedicated Exchange hybrid application in Entra ID. |
Trust credentials and hybrid services remain part of the response
CISA required agencies to reset the first-party service principal key credential. It also said Exchange Web Services calls from Exchange Server to Exchange Online will be deprecated and that the change will be enforced starting October 2025, with Microsoft Graph API planned for hybrid functionality.
CISA published its report on Aug 7, 2025.
Microsoft said Exchange Online customers do not need to take action because it deployed a related service-side fix. Users of affected on-premises Exchange Server products were advised to install the updates.
CISA said it will continue identifying instances and potential compromises associated with the activity, notify partners and issue further guidance as appropriate.
What to do now
- Install the latest cumulative update supported by the environment, including Exchange 2019 CU14 or CU15, and apply the April 2025 hotfix updates.
- Replace the legacy shared service principal with the new dedicated hybrid app in Entra ID.
FAQ
What is CVE-2026-96940?
It is a Microsoft Exchange Server vulnerability rated 8.8 on CVSS that could allow an authenticated attacker to elevate privileges over a network.
Which Microsoft Exchange versions are affected?
Microsoft listed Exchange Server Subscription Edition RTM, Exchange Server 2016 Cumulative Update 23, and Exchange Server 2019 Cumulative Updates 14 and 15 among the impacted versions.
Can CVE-2026-96940 access Exchange mailboxes?
Microsoft said an authenticated attacker can access other users’ mailboxes and read email messages and attachments within the same organization. The flaw does not allow cross-tenant access.
Has CVE-2026-96940 been exploited?
Microsoft said there is no evidence that the flaw has been weaponized in the wild. CISA said exploitation is possible only after an attacker establishes administrative access on the on-premises Exchange server.
How do I fix CVE-2026-96940?
Microsoft advised users of affected on-premises Exchange Server products to install the updates. CISA also required agencies to apply the latest cumulative updates and April 2025 hotfix updates.
What is the impact on Exchange Online customers?
Microsoft said it deployed a related service-side fix to Exchange Online, so Exchange Online customers are not required to take action.
Sources
- ED 25-02: Mitigate Microsoft Exchange Vulnerability | CISA, CISAPrimary
- Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes, The Hacker News
- 29,000 Servers Remain Unpatched Against Microsoft Exchange Flaw, CISA
- Nearly 30,000 Microsoft Exchange servers remain unpatched against critical hybrid flaw, SiliconANGLE
How we checked this story
| Claim | Source | Status |
|---|---|---|
| Microsoft released out-of-band security updates for a high-severity Microsoft Exchange Server flaw that could allow privilege escalation under certain conditions. | Microsoft, via The Hacker News | Attributed |
| Microsoft Exchange Server CVE-2026-96940 is rated 8.8 on the CVSS scoring system. | Microsoft, via The Hacker News | Attributed |
| Microsoft said weak authorization allows an authenticated attacker to elevate privileges over a network. | Microsoft, via The Hacker News | Attributed |
| Microsoft said an authenticated attacker can access other users’ mailboxes and read email messages and attachments within the same organization. | Microsoft, via The Hacker News | Attributed |
| Microsoft said the vulnerability does not allow cross-tenant access. | Microsoft, via The Hacker News | Attributed |
| Microsoft deployed a related service-side fix to Exchange Online, so Exchange Online customers do not need to take action. | Microsoft, via The Hacker News | Attributed |
| Microsoft Exchange Server Subscription Edition RTM is among the impacted versions. | Microsoft, via The Hacker News | Attributed |
| Microsoft Exchange Server 2016 Cumulative Update 23 is among the impacted versions. | Microsoft, via The Hacker News | Attributed |
| Microsoft Exchange Server 2019 Cumulative Update 15 is among the impacted versions. | Microsoft, via The Hacker News | Attributed |
| Microsoft Exchange Server 2019 Cumulative Update 14 is among the impacted versions. | Microsoft, via The Hacker News | Attributed |
| Microsoft credited researcher Jan Mitchell with discovering and reporting the flaw. | Microsoft, via The Hacker News | Attributed |
| Microsoft said there is no evidence that the flaw has been weaponized in the wild. | Microsoft, via The Hacker News | Attributed |
| Microsoft assigned the flaw an Exploitability assessment of Exploitation More Likely. | Microsoft, via The Hacker News | Attributed |
| Shadowserver found 29,098 vulnerable Microsoft Exchange servers worldwide in recent scans. | Shadowserver Foundation | Attributed |
| CISA issued Emergency Directive 25-02 ordering federal agencies to mitigate the flaw by 9:00 a.m. EDT on August 11. | CISA | Attributed |
| CISA said the vulnerability poses a grave risk to organizations operating Microsoft Exchange hybrid-joined configurations that have not followed the April 2025 patch guidance. | CISA | Attributed |
| Microsoft said the vulnerability allows attackers with administrator access to an on-premises server to escalate privileges in the connected cloud environment and potentially compromise the entire domain. | Microsoft, via SiliconANGLE | Attributed |
| Shadowserver counted 29,098 exposed Exchange servers as of August 10, with the highest concentrations in the United States, Germany and Russia. | Shadowserver Foundation, via SiliconANGLE | Attributed |
| CISA issued Emergency Directive 25-02 on August 7 for federal agencies, requiring immediate mitigation. | CISA, via SiliconANGLE | Attributed |
| CISA said exploitation is possible only after an attacker establishes administrative access on the on-premises Exchange server. | CISA | Confirmed |
| CISA required agencies to run Microsoft’s Exchange Server Health Checker script and identify their current cumulative update levels. | CISA | Confirmed |
| CISA required agencies to disconnect Exchange servers that were not eligible for the April 2025 hotfix updates. | CISA | Confirmed |
| CISA required agencies to reset the first-party service principal key credential. | CISA | Confirmed |
| CISA said EWS calls from Exchange Server to Exchange Online will be deprecated and that the change will be enforced starting October 2025. | CISA | Confirmed |
| CISA said it would continue identifying instances and potential compromises associated with the threat activity. | CISA | Confirmed |
| CISA published its report on Aug 7, 2025. | CISA | Confirmed |
Could not verify
- Whether the vulnerability has been exploited in the wild is not established beyond Microsoft’s statement.
- How many Exchange Server installations are affected is not established.
- Whether any organizations or mailboxes were compromised is not established.
- Whether Microsoft Exchange Online’s service-side fix fully addresses affected on-premises deployments is not established.



