CVE-2026-96940 Exchange Flaw: Who Must Patch V2 Now
Quick answer: Microsoft reissued its September 2026 Exchange Server security updates as a V2 release on October 2 to add a fix for CVE-2026-96940. The vulnerability affects supported Exchange Server Subscription Edition RTM and eligible Exchange Server 2019/2016 installations. Microsoft says Exchange Online is already protected, but organizations with on-premises Exchange servers or Exchange Management Tools should apply the V2 update even if they installed the original September security update.
What is CVE-2026-96940?
CVE-2026-96940 is an Exchange Server elevation-of-privilege vulnerability caused by weak authorization. Microsoft rates it Important and the CVSS 3.1 base score is 8.8. The attack requires an authenticated account, but successful exploitation can let that account gain unauthorized access to other users’ mailboxes inside the same organization.
Microsoft says the issue does not provide access across tenant boundaries. The Exchange team also says Microsoft identified the vulnerability internally and was not aware of active exploitation when the V2 update was published.
Which Exchange versions need the V2 security update?
| Exchange product | Update status |
|---|---|
| Exchange Server Subscription Edition RTM | Install the September 2026 V2 security update |
| Exchange Server 2019 CU14 | V2 update available to Period 2 ESU customers |
| Exchange Server 2019 CU15 | V2 update available to Period 2 ESU customers |
| Exchange Server 2016 CU23 | V2 update available to Period 2 ESU customers |
| Exchange Online only | Already protected service-side |
Exchange Server 2016 and 2019 are out of support. Microsoft says the new security updates for those branches are available only to organizations enrolled in the Period 2 Extended Security Update program.
Why the original September 2026 update is not enough
The most important operational detail is that Microsoft released a V2 of the September Exchange security updates specifically to add CVE-2026-96940. Installing the original September update does not mean the server has this particular fix.
Microsoft’s Exchange team says the difference between the original release and V2 is the addition of CVE-2026-96940. Administrators who patched in September should therefore check the installed build rather than assuming the earlier security update covers the issue.
Does Exchange Online need action?
Cloud-only Exchange Online customers do not need to deploy a server patch for this vulnerability because Microsoft says Exchange Online is already protected. Hybrid organizations are different: if they still operate an Exchange server on-premises, even one used only for management, Microsoft recommends installing the V2 security update on that server.
What should Exchange administrators do?
- Inventory every Exchange server and Exchange Management Tools workstation in the environment.
- Run Microsoft’s Exchange Server Health Checker to identify systems that are behind on cumulative or security updates.
- Install the September 2026 V2 security update appropriate for the current Exchange branch.
- Reboot when installation is complete and confirm all Exchange services start normally.
- For hybrid deployments, follow Microsoft’s guidance if authentication certificates or Hybrid Configuration Wizard settings change.
- Review the V2 known issues before deployment, especially in environments using published calendars or Korean-language email processing.
What if you still run Exchange 2016 or 2019?
Microsoft says Exchange 2016 and 2019 customers need Period 2 ESU enrollment to receive the October V2 security updates. The company recommends moving organizations that are not enrolled to Exchange Server Subscription Edition so they can continue receiving current fixes.
This makes CVE-2026-96940 more than a normal patching story for older installations: administrators may discover that the supported remediation path requires a migration rather than simply downloading a public update.
Is CVE-2026-96940 being exploited?
Microsoft says it was not aware of active exploitation when it published the V2 update. That does not eliminate risk. The vulnerability is network reachable, requires low privileges and no user interaction after authentication, according to the published CVSS vector. Microsoft recommends customers apply the update at the earliest opportunity.
Known issues in the September 2026 V2 release
Microsoft lists two known issues with this V2 Exchange release: published calendar .ics requests can return HTTP 500 in some calendar applications, and a ContentEngine deadlock can affect environments processing Korean-language email because of missing WordBreaker rule files. Microsoft says fixes are planned in future updates.
Those known issues should be weighed against the security risk, but Microsoft’s guidance is still to deploy the security update rather than uninstall it.
Frequently asked questions
What does CVE-2026-96940 allow an attacker to do?
Microsoft describes it as an elevation-of-privilege flaw. An authenticated attacker may be able to access other users’ mailboxes within the same organization.
Do I need the V2 update if I installed September’s Exchange security update?
Yes. Microsoft says V2 adds the CVE-2026-96940 fix, which was not part of the original September release.
Does Exchange Online need to be patched by customers?
No server-side action is required for Exchange Online itself because Microsoft says it is already protected. Hybrid customers still need to patch any on-premises Exchange servers and relevant management-tools systems.
Are Exchange 2016 and 2019 still supported?
They are out of normal support. Microsoft is providing these 2026 updates only through the Period 2 ESU program for eligible customers.
Has Microsoft seen active exploitation?
Microsoft’s Exchange team said it identified the flaw internally and was not aware of active exploitation when the update was released.
Sources
- Microsoft Exchange Team: September 2026 V2 security updates
- Microsoft Security Response Center: CVE-2026-96940
For more security and software updates, browse AVARIXO AI & Tech.
