The question
What we told them
It depends on one thing: where your mail lives. If it is in Microsoft 365, you are already covered. If it is on an Exchange server you run yourself, you have work to do today.
Here is what happened. On 2 Oct 2026, Microsoft disclosed CVE-2026-96940, rated 8.8 out of 10. The cause is weak authorization. A person who is already signed in can reach other users' mailboxes in the same organization. They can read the email and the attachments. They cannot cross into another company's tenant. (The Hacker News, 2 Oct 2026.)
Microsoft fixed Exchange Online on its own servers, so cloud customers need to do nothing. The affected on-premises versions are Exchange Server Subscription Edition, Exchange Server 2016 CU23, and Exchange Server 2019 CU14 and CU15. Those need the security update installed by hand.
Microsoft has not seen it used in attacks. It also rates exploitation "more likely." That is the part to take seriously. The attacker needs a valid login first. In a small business, one phished password is often enough to get one.
Our opinion: an Exchange server in the closet is a liability for a company under 50 people. Patching it is a chore someone has to own, and flaws like this one are why. If you are keeping it for habit, this is a good week to price the move to Microsoft 365. If you are keeping it for a real reason, put its patching on a calendar with a name next to it.
First steps, in order. Confirm where your mail lives. If it is on-premises, check the build number against the list above and install the update. Then check that every mailbox login has MFA, because the flaw needs a login to start.
Find out this week whether your email runs on your own Exchange server or in Microsoft 365. Cloud: nothing to do. Your own server: install Microsoft's 2 Oct 2026 security update now, and make sure every account has MFA.