Microsoft has released a second version of its September 2026 Exchange Server security updates after identifying an additional authorization vulnerability that can expose mailboxes inside an organization. Administrators who installed the original September packages should not assume they are fully protected: the newly issued V2 updates add the fix for CVE-2026-96940.
The vulnerability carries a CVSS score of 8.8 and affects on-premises Exchange deployments. An attacker must already have authenticated access, but successful exploitation could allow that account to reach another user’s mailbox and obtain messages or attachments. The weakness requires no user interaction and is described as improper or insufficient authorization over a network.
Microsoft discovered the issue internally and says it is not aware of active exploitation. The reported access remains within the same organization rather than crossing Microsoft 365 tenant boundaries. Even with those limitations, mailbox contents routinely include sensitive business discussions, credentials, recovery links and attachments that could help an attacker deepen an intrusion.
Why the V2 designation matters
The revised release adds protection that was not included in the original September security update. Organizations that patched earlier in the month therefore need to review their Exchange estate again and deploy the package matching each installed product and cumulative-update level.
Updates are available for Exchange Server Subscription Edition RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23. Administrators should verify the precise build before installation rather than applying a package intended for another cumulative update. Microsoft released the fix ahead of its planned schedule, so some supporting documentation may have lagged behind the packages when they first appeared.
CVE-2026-96940 is separate from CVE-2026-62911, an earlier Exchange issue associated with a demonstrated authentication-relay path. Public proof-of-concept material for the older bug is not evidence that exploit code exists for the new authorization flaw. Keeping the two vulnerabilities distinct is important for accurate detection and remediation.
Legacy Exchange versions require special attention
Exchange Server 2016 and 2019 are outside their normal support periods. Their latest security fixes are available only to organizations enrolled in Microsoft’s Period 2 Extended Security Update program, which covers May through October 2026 and requires a separate purchase even for customers that joined an earlier ESU phase.
Microsoft says there will be no extension beyond October, making migration planning urgent for organizations still relying on those releases. Moving to Exchange Server Subscription Edition provides a supported path for continued security updates, but migrations must account for integrations, compliance requirements and hybrid identity dependencies.
Exchange Online customers are already protected from the vulnerabilities addressed by this release. Hybrid customers still have work to do: any local Exchange server must be updated, including servers retained only for recipient management. Systems with Exchange Management Tools also require the applicable updates. A lightly used management server remains part of the attack surface.
A safe patching sequence
Exchange updates are cumulative, so a server on a supported cumulative update does not need every earlier security update installed one by one. Administrators can use Microsoft’s Exchange Update Wizard to identify the correct route and the Exchange Server Health Checker script to find missing cumulative updates, security packages and required manual actions.
A practical rollout should include:
- Inventorying every production, disaster-recovery, hybrid-management and tools-only Exchange system.
- Confirming the installed version and cumulative update before selecting the V2 package.
- Backing up configuration and validating recovery procedures before maintenance.
- Installing the update, restarting the server and checking that Exchange services return normally.
- Running Health Checker again and reviewing event, authentication and mailbox-access logs.
Organizations should also monitor for unusual access from already authenticated accounts, because the flaw’s prerequisite means a compromised user could potentially abuse permissions without sending a malicious attachment. Strong multifactor authentication and careful session monitoring reduce the chance of obtaining the initial account but do not replace the server fix.
Known issues should not delay risk decisions
Microsoft lists known problems involving published calendar files returning HTTP 500 responses and ContentEngine deadlocks affecting Korean-language email. Future updates are expected to address those issues. The release also includes corrections involving shared-mailbox wrapper messages and delegated-mailbox availability in some hybrid configurations.
Administrators should test the package against their operational requirements and watch service health closely after deployment. For most affected organizations, the priority is to close the cross-mailbox authorization gap promptly while following a controlled change process. The central lesson is simple: installing the first September update is not enough; protection against CVE-2026-96940 requires the revised V2 release.
Leave a Reply
You must be logged in to post a comment.