Microsoft Pushes New Exchange V2 Update After Discovering New Security Flaw
Microsoft reissued September 2026 Exchange updates to fix CVE-2026-96940, an authenticated mailbox-access flaw scored 8.8.
Microsoft released September 2026 V2 security updates for on-premises Exchange Server after finding CVE-2026-96940, a weak-authorization flaw scored CVSS 8.8. An authenticated attacker can access other users' mailboxes and attachments inside the same organization without user interaction; access does not cross tenants. Microsoft said it found the bug internally and is not aware of exploitation. Packages cover Subscription Edition RTM, Exchange 2019 CU14 and CU15, and Exchange 2016 CU23, with the older versions limited to Period 2 Extended Security Updates. The issue is separate from CVE-2026-62911, which previously had a public authentication-relay proof of concept.
- CVE-2026-96940 lets authenticated attackers read other users' mailboxes in the same organization.
- CVSS 8.8; no user interaction; Microsoft reports no known active exploitation.
- September 2026 V2 updates cover Subscription Edition, 2019 CU14/CU15, and 2016 CU23.
- Exchange 2016 and 2019 patches require Period 2 Extended Security Updates through October 2026.
- Hybrid and management-tool servers still need patching; Exchange Online is already protected.
Vulnerabilities mentionedAll →
- CVE-2026-629118.01%Capture-Replay Authentication Bypass in Microsoft Exchange Serverpublished · microsoft exchange server
- CVE-2026-969408.8<1%Weak authorization privilege escalation in Microsoft Exchange Server
Full article609 words · extracted from cybersecuritynews.com · click to collapse
Microsoft has released September 2026 V2 security updates to fix an Exchange Server flaw that lets authenticated attackers access other users’ mailboxes within the same organization. Tracked as CVE-2026–96940, the vulnerability could expose email messages and attachments, making it a serious concern for businesses running Exchange on-premises.
The flaw involves weak authorization, allowing an attacker with authenticated access to gain privileges over a network. Public vulnerability records list a CVSS score of 8.8. Unlike attacks that require someone to open a malicious file, exploitation does not require user interaction. The reported mailbox access does not extend across tenant boundaries.
Microsoft said its own teams discovered the vulnerability internally and were not aware of active exploitation. The company also confirmed that the update appeared ahead of its planned release schedule, and some supporting documentation may have been unavailable when the announcement went live.
Microsoft Reissues Exchange Server Update
The September 2026 V2 release adds protection against CVE-2026-96940 to the original September security updates. Organizations that installed the earlier release should therefore review the new packages rather than assume their servers already have this additional fix.
Updates are available for Exchange Server Subscription Edition RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23. Administrators must select the package that matches their installed version and cumulative update.
The new issue is separate from CVE-2026-62911, an earlier Exchange vulnerability covered by Cybersecurity News after a public proof of concept demonstrated an authentication relay attack path. That earlier research should not be treated as evidence that an exploit exists for CVE-2026-96940.
Exchange Server 2016 and 2019 are out of support. Their latest patches are available only to organizations enrolled in Microsoft’s Period 2 Extended Security Update program, which covers May through October 2026.
Period 2 requires a separate purchase, even for customers who joined the earlier ESU program. Microsoft says there will be no further extensions after October. Organizations without this coverage should migrate to Exchange Server Subscription Edition to continue receiving current security updates.
Exchange Online customers are already protected against the vulnerabilities addressed in this release. However, businesses using hybrid deployments must still update their local Exchange servers, including servers used only for management. Machines running Exchange Management Tools also need the applicable updates.
Microsoft recommends running the Exchange Server Health Checker script to identify missing cumulative updates, security updates, and required manual actions. Administrators can use the Exchange Update Wizard to plan the correct upgrade path before installing the latest security package.
Exchange security updates are cumulative. A server running a supported cumulative update does not need every previous security update installed in sequence. After installation, administrators should restart the server, confirm Exchange services start correctly, and run Health Checker again to identify remaining steps.
The release has known issues involving published calendar files returning HTTP 500 errors and ContentEngine deadlocks affecting Korean language email. Microsoft plans to address these in future updates. It also lists fixes for shared mailbox wrapper messages and delegated mailbox availability in certain hybrid environments.
Microsoft urges customers to review deployment guidance and apply the update at the earliest opportunity. For affected organizations, the priority is closing the mailbox access gap while checking that mail services remain healthy after patching across their Exchange environment.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.