Exchange Server CVE-2026-96940: an authenticated user can read other users' mailboxes, install the September 2026 V2 security updates
EditorialBy TrustList Editorial
Microsoft fixed CVE-2026-96940 (CVSS 8.8) in the September 2026 V2 Exchange Server security updates of 2 October. A signed-in user can reach other mailboxes in the same organisation. Exchange 2016/2019 updates need ESU enrolment.
- Cybersecurity
- Patch Management
- Vulnerability Management
- United States
About Exchange Server CVE-2026-96940: an authenticated user can read other users' mailboxes, install the September 2026 V2 security updates
Exchange Server CVE-2026-96940: an authenticated user can read other users' mailboxes, install the September 2026 V2 security updates
2 October 2026 — Microsoft released a second round of Exchange Server security updates for September on 2 October 2026, labelled "September 2026 V2". It adds a fix for CVE-2026-96940, a weak-authorisation flaw in on-premises Exchange that lets an authenticated attacker gain access to other users' mailboxes, including messages and attachments, within the same organisation. Microsoft rates it Important with a CVSS score of 8.8 and marks exploitation as "more likely". It says the flaw was not publicly disclosed before the fix and that it has seen no exploitation.
Who is affected
The flaw is in self-hosted Exchange: Exchange Server Subscription Edition (SE) RTM, Exchange Server 2019 Cumulative Updates 14 and 15, and Exchange Server 2016 Cumulative Update 23. Exchange Online has already been fixed on the service side, so organisations that only use Microsoft 365 mailboxes have nothing to install.
There is a licensing catch. Exchange 2016 and 2019 reached the end of support in October 2025, and Microsoft publishes their security updates only to organisations enrolled in the second period of its paid Extended Security Update programme. An organisation still running either version without that enrolment does not receive this fix, and Microsoft's advice for it is to move to Exchange SE.
Why it matters
The attacker needs a valid account, so this is not an internet-wide, unauthenticated hole. But a single phished or reused password, or a malicious insider, would be enough to read the mail of executives, finance staff or HR within the organisation. Mailbox access of that kind is the usual first step in invoice fraud and in data-theft extortion. Cross-tenant access is not possible, according to Microsoft.
Known issues
Microsoft lists known issues with the V2 updates, including HTTP 500 errors when opening some calendar .ics links and a deadlock involving the Korean word breaker in search. Check the Exchange Team post before scheduling the update on servers where either matters.
What to do
- Identify every on-premises Exchange server, including hybrid management servers kept only for recipient administration, and record its version and Cumulative Update.
- Install the September 2026 V2 security update for that version. Servers on older Cumulative Updates must first be brought to a supported one.
- For Exchange 2016 or 2019, confirm ESU Period 2 enrolment. If you are not enrolled, plan the move to Exchange SE or to Exchange Online, and treat the server as unpatched until then.
- Review mailbox audit logs for access to mailboxes by accounts that should not hold permissions on them.
Company profile on TrustList: Microsoft
Sources
Categories & features
- Cybersecurity
- Patch Management
- Vulnerability Management
- United States
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.