Microsoft re-released its September 2026 Security Updates (SUs) for on-premises Exchange Server. The new “V2” packages add a fix for CVE-2026-96940, an authorization flaw that can let a signed-in user reach mailboxes that are not their own.

If you installed the original September update, your servers are not protected against this issue. The V2 package must be installed on top. Microsoft has acknowledged the update shipped ahead of its planned schedule and has asked administrators to apply it at the earliest opportunity.

Reading our article? Try our product:

Full Protection for Windows Servers - Zero-Risk Trial

CVE-2026-96940

CVE-2026-96940 is an elevation of privilege vulnerability caused by weak authorization checks in Exchange Server. An attacker who already holds valid credentials in the organization can abuse it over the network to open other users’ mailboxes, exposing email and attachments.

AttributeDetail
TypeElevation of privilege (weak authorization)
CVSS score8.8 (High)
Attack vectorNetwork, authenticated user required
User interactionNone
ImpactAccess to other mailboxes in the same organization; does not cross tenant boundaries
Discovered byMicrosoft, internally
Exploited in the wildNot known at time of writing

Microsoft’s exploitability assessment rates exploitation as more likely. This vulnerability is unrelated to CVE-2026-62911, the August pre-authentication relay chain demonstrated at Pwn2Own Berlin 2026. No public exploit for CVE-2026-96940 has been reported.

Affected versions

The V2 update is available for three Exchange builds. Exchange 2016 and 2019 are out of support, so their packages are only available to organizations enrolled in Microsoft’s Period 2 Extended Security Update (ESU) program.

Exchange versionSupported buildHow to obtain
Exchange Server Subscription Edition (SE)RTMKB5129955
Exchange Server 2019CU14, CU15Period 2 ESU only
Exchange Server 2016CU23Period 2 ESU only

Period 2 ESU covers updates released between May and October 2026, requires a separate purchase from the first ESU period, and Microsoft has said it will not be extended. Organizations still on Exchange 2016 or 2019 without Period 2 coverage are not receiving this fix and should plan their move to Exchange SE now.

Exchange Online and hybrid environments

Exchange Online is already protected and needs no action. Hybrid organizations are a different story: every on-premises Exchange server must be patched, including servers kept only for recipient management.

Microsoft also recommends updating any workstation or server running the Exchange Management Tools, to keep clients and servers compatible. If you change the Exchange auth certificate after installing the update, re-run the Hybrid Configuration Wizard.

Next steps

Security updates are cumulative, so servers on a supported CU only need the latest V2 package, not every previous SU in sequence.

  1. Run the Exchange Server Health Checker script to inventory servers and find missing CUs, SUs or manual actions.
  2. Confirm each server is on a supported CU; use the Exchange Update Wizard to plan any CU upgrade first.
  3. Install the September 2026 V2 SU that matches your version and CU, from an elevated prompt.
  4. Reboot, then confirm all Exchange services have started. Disabled services usually mean the install was interrupted.
  5. Run Health Checker again. If setup errors occur, use the SetupAssist script and Microsoft’s repair guidance.

Known issues: Two problems remain open and are slated for a future update: published calendar (.ics) links may return HTTP 500 errors, and the ContentEngine can deadlock on Korean-language email due to missing WordBreaker rule files.

Fixed in this release: The V2 update resolves wrapper messages appearing in shared mailbox inboxes in hybrid setups, and free/busy failures for delegated mailboxes in Graph API-only hybrid deployments.

Why credentials are the real front line

CVE-2026-96940 requires a valid login, which makes stolen or guessed credentials the attacker’s starting point. Patching closes this specific gap; stopping password attacks against Exchange closes the door that leads to it, and the next authorization flaw like it.

It also continues a busy year for Exchange security, following the exploited CVE-2026-42897 in May and CVE-2026-62911 in August. Organizations running Exchange on-premises should treat patching and access protection as ongoing work, not a one-off.

Fortify Your Server with Messageware Security

Data breaches have increased by 72%, servers are compromised in under 90 minutes. Ensure you have multiple layers of security software protecting your Windows Servers.

Server Threat Guard (STG) for All Windows Servers: Next-gen server protection, providing detection, alerting, and response (MDR) to zero-day and server penetration cyber-attacks. No need to research complicated deployments and no learning curve to install and manage.

EPG Guard for Exchange Servers: Real-time security. Stop AD account lockouts, eliminate password attacks, intelligent GEO blocking, and prevent Exchange Server vulnerability probing.

Don’t leave your critical infrastructure vulnerable, be proactive and stay ahead of evolving threats.