Exchange bug could expose coworkers’ email and attachments

Exchange bug could expose coworkers’ email and attachments. An authenticated attacker could read other users’ emails and attachments because of a high-severity authorization weakness in Exchange Server.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Tuesday, October 6th, 2026.

An authenticated attacker could read other users’ emails and attachments because of a high-severity authorization weakness in Exchange Server. The access is limited to people in the same organization and does not cross tenant boundaries.

Microsoft has released an out-of-band update for supported on-premises Exchange versions. It also deployed a related service-side fix for Exchange Online. The company says it is not aware of active exploitation, but it considers the issue consistently exploitable and recommends updating promptly.

Mailbox access can reveal confidential conversations, invoices, contracts, attachments, and information that supports convincing impersonation. An attacker who already controls one valid account could therefore gain much more value from that initial access.

For leaders, the important point is that a valid login does not necessarily limit the scope of potential data exposure. For defenders, patch every Exchange server and every workstation or server running Exchange Management Tools. Deploy the September 2026 v2 update, verify that installation succeeded, and review the environment for unusual mailbox access involving authenticated accounts.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

Exchange bug could expose coworkers’ email and attachments
Broadcast by