Microsoft has released September 2026 V2 security updates to fix an Exchange Server flaw that lets authenticated attackers access other users’ mailboxes within the same organization. Tracked as CVE-2026–96940, the vulnerability could expose email messages and attachments, making it a serious concern for businesses running Exchange on-premises.
The flaw involves weak authorization, allowing an attacker with authenticated access to gain privileges over a network. Public vulnerability records list a CVSS score of 8.8. Unlike attacks that require someone to open a malicious file, exploitation does not require user interaction. The reported mailbox access does not extend across tenant boundaries.
Microsoft said its own teams discovered the vulnerability internally and were not aware of active exploitation. The company also confirmed that the update appeared ahead of its planned release schedule, and some supporting documentation may have been unavailable when the announcement went live.
Microsoft Reissues Exchange Server Update
The September 2026 V2 release adds protection against CVE-2026-96940 to the original September security updates. Organizations that installed the earlier release should therefore review the new packages rather than assume their servers already have this additional fix.
Updates are available for Exchange Server Subscription Edition RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23. Administrators must select the package that matches their installed version and cumulative update.
The new issue is separate from CVE-2026-62911, an earlier Exchange vulnerability covered by Cybersecurity News after a public proof of concept demonstrated an authentication relay attack path. That earlier research should not be treated as evidence that an exploit exists for CVE-2026-96940.
Exchange Server 2016 and 2019 are out of support. Their latest patches are available only to organizations enrolled in Microsoft’s Period 2 Extended Security Update program, which covers May through October 2026.
Period 2 requires a separate purchase, even for customers who joined the earlier ESU program. Microsoft says there will be no further extensions after October. Organizations without this coverage should migrate to Exchange Server Subscription Edition to continue receiving current security updates.
Exchange Online customers are already protected against the vulnerabilities addressed in this release. However, businesses using hybrid deployments must still update their local Exchange servers, including servers used only for management. Machines running Exchange Management Tools also need the applicable updates.
Microsoft recommends running the Exchange Server Health Checker script to identify missing cumulative updates, security updates, and required manual actions. Administrators can use the Exchange Update Wizard to plan the correct upgrade path before installing the latest security package.
Exchange security updates are cumulative. A server running a supported cumulative update does not need every previous security update installed in sequence. After installation, administrators should restart the server, confirm Exchange services start correctly, and run Health Checker again to identify remaining steps.
The release has known issues involving published calendar files returning HTTP 500 errors and ContentEngine deadlocks affecting Korean language email. Microsoft plans to address these in future updates. It also lists fixes for shared mailbox wrapper messages and delegated mailbox availability in certain hybrid environments.
Microsoft urges customers to review deployment guidance and apply the update at the earliest opportunity. For affected organizations, the priority is closing the mailbox access gap while checking that mail services remain healthy after patching across their Exchange environment.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

