Exchange Server September 2026 V2 update adds CVE-2026-96940 mailbox-access flaw fix: install it on every Exchange server
EditorialBy TrustList Editorial
Microsoft re-released the September 2026 Exchange security updates on 2 October to add CVE-2026-96940 (CVSS 8.8): a signed-in user could read other mailboxes in the same organisation. Hybrid and management-tools servers need it too.
- United States
- Redmond, Wa
- Cybersecurity
- Patch Management
- +2 more
About Exchange Server September 2026 V2 update adds CVE-2026-96940 mailbox-access flaw fix: install it on every Exchange server
Exchange Server September 2026 V2 update adds CVE-2026-96940 mailbox-access flaw fix: install it on every Exchange server
2 October 2026 — Microsoft re-released the September 2026 security updates for Exchange Server on 2 October 2026. The only difference from the original release is one added vulnerability, CVE-2026-96940, which Microsoft rates Important with a CVSS score of 8.8. Anyone who installed the September updates before 2 October still needs the V2 package, because the first release does not contain this fix.
Not yet independently verified. Both sources are Microsoft. Microsoft rates the flaw not publicly disclosed and not exploited; no independent report on it had been read at 2026-10-03. Fixed build numbers were read from the Security Update Guide data feed, not from the KB pages. We will update this when it can be confirmed, and remove this note.
What changed
Microsoft's Security Update Guide describes CVE-2026-96940 as weak authorisation in Exchange Server that lets an authenticated attacker raise their privileges over the network. In its FAQ, Microsoft explains the effect: a signed-in attacker could gain unauthorised access to other users' mailboxes within the same organisation and read messages and attachments. It does not cross tenant boundaries.
Microsoft lists the flaw as not publicly disclosed and not exploited, but with the assessment "Exploitation More Likely". Exchange Online already received a related service-side fix, so cloud-only customers do nothing.
The fixed builds listed by Microsoft are:
- Exchange Server Subscription Edition RTM: KB5129955, build 15.02.2562.053
- Exchange Server 2019 CU15: KB5129956, build 15.02.1748.053
- Exchange Server 2019 CU14: KB5129957, build 15.02.1544.048
- Exchange Server 2016 CU23: KB5129958, build 15.01.2507.075
The V2 package also lists two known issues: published calendar (.ics) links can return HTTP 500, and a content-indexing deadlock can affect mailboxes with Korean-language mail. Microsoft says both will be addressed in a future update. Two hybrid-related fixes are included, covering wrapper messages in shared mailboxes and free/busy lookups for delegated mailboxes.
Who is affected
Any organisation running Exchange Server on premises, including hybrid setups where the on-premises servers exist only for management. Microsoft says the update must go on every Exchange server and on every server or workstation that runs the Exchange Management Tools.
Exchange 2016 and 2019 are out of support. Their security updates released between May and October 2026 are available only to organisations enrolled in the Period 2 Extended Security Update programme. Organisations outside that programme cannot obtain these fixes and Microsoft's stated answer is to migrate to Exchange Server Subscription Edition.
What to do
- Run the Exchange Health Checker script to list which servers are behind on cumulative or security updates.
- Confirm each server runs a cumulative update the V2 package supports (SE RTM, 2019 CU14 or CU15, 2016 CU23). Updates are cumulative, so you only need the latest one, not every earlier release.
- Install the V2 update on every Exchange server and every machine with the Management Tools, then reboot and check that all Exchange services started. Microsoft notes that disabled services point to an interrupted installation.
- If you change the authentication certificate after installing, re-run the Hybrid Configuration Wizard.
- If you run Exchange 2016 or 2019 without the Period 2 ESU, put Subscription Edition migration on this quarter's plan; otherwise this and later fixes will not reach you.
- Tell your mailbox owners nothing changes for them, but audit for unusual mailbox access by internal accounts if the V2 update was not applied before now.
Sources
Categories & features
- United States
- Redmond, Wa
- Cybersecurity
- Patch Management
- Vulnerability Management
- Email Management
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More United StatesThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.