Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users’ Mailboxes

A critical vulnerability in Microsoft Exchange has been discovered, allowing authenticated attackers to access and read other users’ mailboxes with ease. The flaw, which affects all supported versions of Exchange Server, poses a significant threat to organizations that rely on the platform for email communication and collaboration.

The issue stems from an incorrect implementation of the Windows Authentication protocol, specifically in the way it handles cross-domain privilege escalation. In simple terms, this means that when a user is authenticated to access their own mailbox, they can potentially use that authentication to access other users’ mailboxes as well – without needing any additional credentials or permissions. This creates a ” lateral movement” attack path, allowing attackers to move freely within an organization’s network and compromise sensitive data.

The vulnerability affects all supported versions of Exchange Server, including those running on-premises and in the cloud. If exploited, it could allow attackers to read emails, calendar events, and other mailbox contents belonging to other users. This is particularly concerning for organizations that use Exchange for email communication between employees or with external partners. A successful attack could lead to sensitive information being exposed or even used for further malicious activities.

To make matters worse, the vulnerability is not limited to direct attacks on individual mailboxes. In a more sophisticated scenario, an attacker could exploit this flaw to access multiple users’ mailboxes, effectively creating a backdoor into an organization’s network. This could be achieved by compromising one user’s account and then using their authentication credentials to gain access to other accounts.

Microsoft has been aware of the issue since at least July 2026 and has taken steps to address it in various patches and updates. However, the company has not yet provided a fix for all supported versions of Exchange Server, which means that organizations using affected versions may still be vulnerable.

To mitigate this risk, it’s essential for organizations to keep their Exchange Servers up-to-date with the latest security patches and consider implementing additional security measures such as multi-factor authentication (MFA) and access controls. By taking these proactive steps, organizations can significantly reduce the likelihood of a successful attack on their email infrastructure.


Source: The Hacker News — 2026-10-05