Exchange Server CVE-2026-96940: Why You Need the September V2 Update Even If You Already Patched

Microsoft re-released its September 2026 Exchange Server security updates as V2 to fix CVE-2026-96940. Servers that installed the original September update are still exposed until V2 is applied.

Why this matters now. On October 2, 2026, Microsoft released an out-of-band security update for on-premises Exchange Server. It fixes CVE-2026-96940, a high-severity authorization flaw (CVSS 3.1 score 8.8) that can let an authenticated user gain access to other users’ mailboxes, including messages and attachments, within the same Exchange organization. The fix shipped as a re-release of the September 2026 Security Updates labelled V2 — servers that installed the original September package are still exposed.

This defender’s note covers what Microsoft has disclosed, which builds close the hole, and a checklist to verify you are on V2. It contains no exploit steps — only publicly published versions, KBs, and defender guidance.

What we know

  • The flaw: weak authorization in Exchange Server that allows an authenticated attacker to elevate privileges over the network and access other mailboxes in the same organization. Microsoft says it does not allow access across tenant boundaries.
  • Exploitation status: Microsoft found the issue internally and says it is not aware of active exploitation. It rates the flaw “Exploitation More Likely” and notes this class of bug has been exploited before, so it recommends updating promptly.
  • Exchange Online: already fixed on the service side. Customers running only Exchange Online need no action.
  • Hybrid environments: on-premises Exchange servers in hybrid deployments, and machines running the Exchange Management Tools, still need the on-prem update.
  • A messy rollout: the Exchange Online fix landed before an explanatory KB article was published, and Microsoft acknowledged the update went out ahead of its intended schedule.

Affected versions and fixed builds

Product Fixed by Fixed build
Exchange Server Subscription Edition RTM KB5129955 15.02.2562.053
Exchange Server 2019 CU15 KB5129956 15.02.1748.053
Exchange Server 2019 CU14 KB5129957 15.02.1544.048
Exchange Server 2016 CU23 KB5129958 15.01.2507.075

Exchange Server 2016 and 2019 receive this update only through the Period 2 Extended Security Update (ESU) program. Organizations on 2016 or 2019 without Period 2 ESU should treat migration to Exchange Server Subscription Edition as the remediation path.

Why it matters even without known exploitation

Mailbox access inside an organization is exactly what attackers want after a phishing or password-spray foothold. A single compromised low-privilege account could become a route into executive, finance, or legal mailboxes. Because the bug requires authentication, it pairs naturally with credential theft, which remains one of the most common initial-access methods we see in assessments.

The V2 naming also creates a real risk of false confidence. Patch dashboards that show “September 2026 SU installed” may not distinguish between the original and V2 packages, so a server can look compliant while still exposed.

Defender checklist

  1. Inventory every Exchange role. Include mailbox servers, hybrid servers, and every server or workstation with the Exchange Management Tools installed. Microsoft recommends installing the SU on all of them.
  2. Verify build numbers, not just the update name. Compare each server against the fixed builds in the table above.
  3. Install the September 2026 V2 SU for your CU, reboot, and confirm Exchange services come back cleanly.
  4. Re-run the Exchange Health Checker after patching to confirm the update is recognized.
  5. Check hybrid configuration. If the auth certificate changed after the update, re-run the Hybrid Configuration Wizard.
  6. Plan for unsupported versions. If you run 2016 or 2019 without Period 2 ESU, there is no supported fix; prioritize migration and tighten access in the meantime.
  7. Watch for unusual mailbox access. Review mailbox audit logs for accounts opening mailboxes they don’t normally access, and keep MFA and password-spray detections in place for any account that can reach Exchange.

The bottom line

If you run Exchange on-premises or in hybrid mode, don’t assume September’s patch covered you. Confirm every server and management host is on the V2 build, and treat this as a priority even though Microsoft hasn’t seen it exploited yet.

Sources