Microsoft has issued a re-release of its September 2026 Exchange Server update—dubbed “V2″—to address a critical new vulnerability that allows attackers with valid credentials to access mailboxes of other users in the same organization. The flaw is cataloged as CVE-2026-96940, and it carries a CVSS score of 8.8, putting it in the high risk category. Unlike many remote exploitation attacks, this vulnerability doesn’t require end-user interaction—once authenticated, an attacker can gain access without tricking a user into opening a malicious file or link. However, the breach is limited to within the same tenant: cross-tenant mailbox access is not possible.
Which Versions Are Affected & What You Should Do
The updated patch is included in the September 2026 V2 rollouts and applies to Exchange Server Subscription Edition RTM, as well as Exchange Server 2019 versions CU14 and CU15, and Exchange Server 2016 CU23. Microsoft emphasizes that organizations which applied earlier September updates must still adopt this new patch, because CVE-2026-96940 is a separate issue introduced after the original release.
Support for Exchange Server 2016 and 2019 in the standard lifecycle has expired. These editions are presently covered only through Microsoft’s Period 2 Extended Security Update (ESU) program, which runs from May through October 2026. After that, patches will cease unless organizations migrate to the Subscription Edition to maintain security support.
While Exchange Online customers are already protected from this vulnerability, those operating hybrid environments or running on-premises instances (including machines that host management tools) still need to apply the fixes. Administrators are encouraged to use Microsoft’s Exchange Server Health Checker script to locate missing updates, verify correct installation, and assess any additional manual tasks required. Additionally, plan your upgrade path using the Exchange Update Wizard before deployment.
Known Side Effects & Post-Patch Steps
This V2 update comes with acknowledged issues. Some organizations may see HTTP 500 errors when accessing published calendar files, and Korean-language email environments could experience content rendering deadlocks. Additional glitches being tracked include shared mailbox wrapper message inconsistencies and delegated mailbox availability concerns in hybrid setups. Microsoft has pledged to resolve these in forthcoming patches.
After installing the patch, organizations should restart affected servers, confirm that all Exchange services have resumed normally, and then rerun the Health Checker tool to ensure no steps were missed. Because updates are cumulative, servers running up-to-date cumulative versions won’t need every previous fix individually.
Despite active discovery by Microsoft’s internal teams, there’s no evidence that CVE-2026-96940 has been exploited in the wild. This differs from some earlier Exchange vulnerabilities that had publicly disclosed proof of concept tooling. Still, attackers should move quickly to remediate the risk.
Analytical Perspective:This incident highlights how even authenticated access can pose grave risks if authorization controls are weak. For organizations relying on on-premises Exchange, this serves as a reminder that patching cadence and clarity about version support (like the upcoming cut-off of ESU coverage) are critical to maintaining security hygiene. Going forward, system admins should audit credential access more tightly, consider migration paths toward Subscription Editions or cloud services, and ensure robust monitoring post-patch to catch any lingering fallout from deployment in complex hybrid environments.