Microsoft Releases Emergency Exchange Server Update to Fix CVE-2026-96940
Microsoft issued a revised September 2026 Exchange Server update (V2) adding a fix for CVE-2026-96940 across Exchange SE, 2019, and 2016.
Microsoft published a V2 replacement for its September 2026 Exchange Server security update on October 2, adding CVE-2026-96940 plus other flaws reported by external partners and internal processes. The update covers Exchange Server Subscription Edition RTM, Exchange 2019 CU14/CU15, and Exchange 2016 CU23, with the legacy versions only patched for organizations enrolled in the Period 2 Extended Security Update program. Exchange Online customers are already protected but should patch any remaining on-premises servers and Exchange Management Tools workstations.
- V2 package (Oct 2) adds CVE-2026-96940 fix missing from original September 2026 update
- Applies to Exchange SE RTM, 2019 CU14/CU15, 2016 CU23; legacy versions require ESU enrollment
- Exchange Online unaffected; hybrid environments must still patch on-premises servers
- Microsoft advises Health Checker script first, then reboot and verify all services start
Vulnerabilities mentionedAll →
- CVE-2026-969408.8<1%Weak authorization privilege escalation in Microsoft Exchange Serverpublished · Microsoft Exchange Server PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-96940 | Weak authorization privilege escalation in Microsoft Exchange Server |
Full article552 words · extracted from gbhackers.com · click to collapse
Microsoft has released a revised security update package for on-premises Exchange Server, dated September 2026, which includes a fix for CVE-2026-96940.
This V2 release applies to Exchange Server Subscription Edition, Exchange Server 2019, and Exchange Server 2016. Customers using Exchange Online are already protected and do not need this update.
The revised update was published on October 2, 2026, as a replacement for the original September 2026 Exchange Server Security Update.
Microsoft noted that this new package addresses CVE-2026-96940, along with other vulnerabilities reported by external security partners and identified through the company’s internal security processes.
Affected Exchange Versions
The September 2026 V2 security updates are available for the following products:
- Exchange Server Subscription Edition: Exchange SE RTM
- Exchange Server 2019: CU14 and CU15, through Period 2 Extended Security Updates (ESU)
- Exchange Server 2016: CU23, through Period 2 ESU
Exchange Server 2016 and Exchange Server 2019 have reached end of support, meaning the September 2026 V2 updates are available only to organizations enrolled in Microsoft’s Period 2 Extended Security Update program. This program provides eligible customers with security updates released between May and October 2026.
Organizations that are not enrolled in the ESU program will not receive the latest fixes for Exchange 2016 and 2019. They should plan to migrate to Exchange Server Subscription Edition to continue receiving security updates.
Microsoft does not list Exchange Online as affected. Customers using the cloud-hosted service do not need to deploy server-side security updates, but they should update any on-premises Exchange servers and Exchange Management Tools workstations that are still part of their environment.
The main addition in the V2 update is CVE-2026-96940, which was not included in the original security update package. Microsoft has directed administrators to the Microsoft Security Update Guide and the associated download knowledge base article for details on the vulnerabilities, including impacted product versions and security recommendations.
This update highlights an operational concern for enterprises running hybrid Exchange environments. Patching only the legacy on-premises infrastructure could leave administrators, management systems, and internet-facing mail servers vulnerable, even if mailboxes have migrated to Exchange Online.
Microsoft recommends that administrators first run the Exchange Server Health Checker script. This script inventories Exchange installations and identifies missing cumulative updates, security updates, or required manual remediation actions.
Before deploying the new security update, organizations should ensure their server is running a supported cumulative update. Administrators can use Microsoft’s Exchange Update Wizard to determine the correct upgrade path for their current Exchange build.
After installation, Microsoft advises rebooting the affected server and verifying that all Exchange services start successfully. If any services are disabled after patching, it may indicate an interrupted installation, which requires remediation before returning the system to production.
For setup failures or post-installation errors, Microsoft recommends using the SetupAssist script and referring to the Exchange update repair guidance.
Microsoft anticipates that both issues will be addressed in future updates. The V2 package also resolves problems with wrapper messages appearing in shared mailbox inboxes in hybrid deployments and delegated mailbox free/busy failures in Graph API-only hybrid environments.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.