Microsoft just patched an Exchange Server bug that lets a logged-in attacker start snooping on coworkers' inboxes.
The flaw, CVE-2026-96940, rated 8.8 out of 10, is a weak-authorization bug that lets an authenticated low-privilege Exchange user escalate privileges and read mailboxes belonging to other people in the same organization. It can't grant admin or SYSTEM access on the underlying server, and it can't be used to cross between tenants. Exchange Online customers are already covered by a server-side fix; only on-prem Exchange Server 2016, 2019, and Subscription Edition need the update, and those on 2016 or 2019 only get it if they're enrolled in Microsoft's Extended Security Update program, since both versions passed end of support last year. Microsoft shipped the fix on October 2, ahead of its normal schedule, as an addition to the September 8 security updates.
The bar for exploitation here is low. A set of credentials bought off the dark web or lifted by a basic phishing kit is enough to get a foothold, after which an attacker can read contracts, invoices, and internal discussions belonging to anyone else in the company - exactly the raw material business email compromise scams run on. Microsoft hasn't confirmed active exploitation, but its own "exploitation more likely" label is doing a lot of the talking.
Nothing's on CISA's known-exploited list yet, but Exchange privilege bugs have a habit of staying quiet right up until they don't.