AVARIXO

Type and hit Enter to search

Microsoft Exchange logo illustrating CVE-2026-96940 Exchange Server security update
AI & Tech

CVE-2026-96940 Exchange Flaw: Who Must Patch V2 Now

AVARIXO
October 8, 2026 4 Mins Read
2 Views
0 Comments

Quick answer: Microsoft reissued its September 2026 Exchange Server security updates as a V2 release on October 2 to add a fix for CVE-2026-96940. The vulnerability affects supported Exchange Server Subscription Edition RTM and eligible Exchange Server 2019/2016 installations. Microsoft says Exchange Online is already protected, but organizations with on-premises Exchange servers or Exchange Management Tools should apply the V2 update even if they installed the original September security update.

What is CVE-2026-96940?

CVE-2026-96940 is an Exchange Server elevation-of-privilege vulnerability caused by weak authorization. Microsoft rates it Important and the CVSS 3.1 base score is 8.8. The attack requires an authenticated account, but successful exploitation can let that account gain unauthorized access to other users’ mailboxes inside the same organization.

Microsoft says the issue does not provide access across tenant boundaries. The Exchange team also says Microsoft identified the vulnerability internally and was not aware of active exploitation when the V2 update was published.

Which Exchange versions need the V2 security update?

Exchange productUpdate status
Exchange Server Subscription Edition RTMInstall the September 2026 V2 security update
Exchange Server 2019 CU14V2 update available to Period 2 ESU customers
Exchange Server 2019 CU15V2 update available to Period 2 ESU customers
Exchange Server 2016 CU23V2 update available to Period 2 ESU customers
Exchange Online onlyAlready protected service-side

Exchange Server 2016 and 2019 are out of support. Microsoft says the new security updates for those branches are available only to organizations enrolled in the Period 2 Extended Security Update program.

Why the original September 2026 update is not enough

The most important operational detail is that Microsoft released a V2 of the September Exchange security updates specifically to add CVE-2026-96940. Installing the original September update does not mean the server has this particular fix.

Microsoft’s Exchange team says the difference between the original release and V2 is the addition of CVE-2026-96940. Administrators who patched in September should therefore check the installed build rather than assuming the earlier security update covers the issue.

Does Exchange Online need action?

Cloud-only Exchange Online customers do not need to deploy a server patch for this vulnerability because Microsoft says Exchange Online is already protected. Hybrid organizations are different: if they still operate an Exchange server on-premises, even one used only for management, Microsoft recommends installing the V2 security update on that server.

What should Exchange administrators do?

  1. Inventory every Exchange server and Exchange Management Tools workstation in the environment.
  2. Run Microsoft’s Exchange Server Health Checker to identify systems that are behind on cumulative or security updates.
  3. Install the September 2026 V2 security update appropriate for the current Exchange branch.
  4. Reboot when installation is complete and confirm all Exchange services start normally.
  5. For hybrid deployments, follow Microsoft’s guidance if authentication certificates or Hybrid Configuration Wizard settings change.
  6. Review the V2 known issues before deployment, especially in environments using published calendars or Korean-language email processing.

What if you still run Exchange 2016 or 2019?

Microsoft says Exchange 2016 and 2019 customers need Period 2 ESU enrollment to receive the October V2 security updates. The company recommends moving organizations that are not enrolled to Exchange Server Subscription Edition so they can continue receiving current fixes.

This makes CVE-2026-96940 more than a normal patching story for older installations: administrators may discover that the supported remediation path requires a migration rather than simply downloading a public update.

Is CVE-2026-96940 being exploited?

Microsoft says it was not aware of active exploitation when it published the V2 update. That does not eliminate risk. The vulnerability is network reachable, requires low privileges and no user interaction after authentication, according to the published CVSS vector. Microsoft recommends customers apply the update at the earliest opportunity.

Known issues in the September 2026 V2 release

Microsoft lists two known issues with this V2 Exchange release: published calendar .ics requests can return HTTP 500 in some calendar applications, and a ContentEngine deadlock can affect environments processing Korean-language email because of missing WordBreaker rule files. Microsoft says fixes are planned in future updates.

Those known issues should be weighed against the security risk, but Microsoft’s guidance is still to deploy the security update rather than uninstall it.

Frequently asked questions

What does CVE-2026-96940 allow an attacker to do?

Microsoft describes it as an elevation-of-privilege flaw. An authenticated attacker may be able to access other users’ mailboxes within the same organization.

Do I need the V2 update if I installed September’s Exchange security update?

Yes. Microsoft says V2 adds the CVE-2026-96940 fix, which was not part of the original September release.

Does Exchange Online need to be patched by customers?

No server-side action is required for Exchange Online itself because Microsoft says it is already protected. Hybrid customers still need to patch any on-premises Exchange servers and relevant management-tools systems.

Are Exchange 2016 and 2019 still supported?

They are out of normal support. Microsoft is providing these 2026 updates only through the Period 2 ESU program for eligible customers.

Has Microsoft seen active exploitation?

Microsoft’s Exchange team said it identified the flaw internally and was not aware of active exploitation when the update was released.

Sources

  • Microsoft Exchange Team: September 2026 V2 security updates
  • Microsoft Security Response Center: CVE-2026-96940

For more security and software updates, browse AVARIXO AI & Tech.

Tags:

Exchange Server update

Share Article

Follow Me Written By

AVARIXO

Other Articles

Phillip Burton Federal Building and United States Courthouse in San Francisco
Previous

Cash App Settlement Payments October 2026: Who Gets Paid

Air Corsica Airbus A320 aircraft representing the October 2026 pilot strike
Next

Air Corsica Pilot Strike October 9-16: Flights at Risk

Next
Air Corsica Airbus A320 aircraft representing the October 2026 pilot strike
October 8, 2026

Air Corsica Pilot Strike October 9-16: Flights at Risk

Previous
October 8, 2026

Cash App Settlement Payments October 2026: Who Gets Paid

Phillip Burton Federal Building and United States Courthouse in San Francisco

No Comment! Be the first one.

    Leave a Reply Cancel reply

    Your email address will not be published. Required fields are marked *

    AVARIXO — Know More. Sooner.
    Gaming AI & Tech Entertainment Internet Alerts Sports Deals Money News & Explainers Travel
    ☰
    Gaming AI & Tech Entertainment Internet Alerts Sports Deals Money News & Explainers Travel
    More⌄
    ⚡Avarixo ToolsCalculators & converters ◈Original DataTrackers & live datasets
    AVARIXO — Know More. Sooner.

    Fast, useful explainers for what people are searching, discussing and deciding right now.

    ☆

    Join readers who trust Avarixo

    Add Avarixo as a preferred source on Google to see more of our guides in your news results.

    Add to Google Preferences →
    © 2026 AVARIXO
    AboutContactPrivacyTerms