Microsoft Reissues Exchange Server Update to Patch Critical Mailbox Access Flaw
Microsoft has released an updated security patch for Exchange Server to address CVE-2026-96940, a critical vulnerability allowing authenticated attackers to access other users' mailboxes.

Microsoft has reissued its September 2026 security updates for Exchange Server, now designated as the V2 release, to address a critical vulnerability identified as CVE-2026-96940. This flaw, which carries a CVSS score of 8.8, permits authenticated attackers to gain unauthorized access to other users' mailboxes within the same organization. The vulnerability stems from weak authorization controls, enabling an attacker with existing credentials to escalate their privileges and read sensitive email messages and attachments.
Unlike many other vulnerabilities, exploitation of CVE-2026-96940 does not require any user interaction, making it a more direct threat to organizations running on-premises Exchange servers. Microsoft stated that its internal teams discovered the vulnerability and confirmed there was no active exploitation in the wild at the time of disclosure. The company also noted that the updated patch was released ahead of its usual schedule, and some accompanying documentation might have been initially unavailable.
The September 2026 V2 release specifically adds protection against CVE-2026-96940 to the original September security updates. Organizations that had already applied the initial September release must now install the V2 packages to ensure they are protected against this new threat. The affected versions include Exchange Server Subscription Edition RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23. Administrators are advised to apply the specific package that matches their installed version and cumulative update.
It is important to note that this new vulnerability is distinct from CVE-2026-62911, another Exchange Server flaw previously reported. The existence of a public proof-of-concept for CVE-2026-62911 should not be misconstrued as evidence of an exploit for CVE-2026-96940.
Microsoft has reiterated that Exchange Server 2016 and 2019 are past their end-of-support dates. Security updates for these versions are exclusively available to organizations enrolled in the Period 2 Extended Security Update (ESU) program, which covers the period from May to October 2026 and requires a separate purchase. No further extensions are planned beyond October 2026. Organizations seeking continuous security updates should migrate to Exchange Server Subscription Edition.
Customers using Exchange Online are already protected against the vulnerabilities addressed in this release. However, businesses operating in hybrid environments must still update their on-premises Exchange servers, including those used solely for management purposes. Servers running only Exchange Management Tools also require the relevant updates.
Microsoft recommends utilizing the Exchange Server Health Checker script to identify any missing cumulative updates, security updates, or required manual actions. Administrators should carefully review the deployment guidance before installing the latest security package. After installation, it is crucial to restart the server, verify that Exchange services are functioning correctly, and re-run the Health Checker script to confirm all necessary steps have been completed.
The release notes for the V2 update also mention known issues, including HTTP 500 errors for published calendar files and ContentEngine deadlocks affecting Korean language emails, which Microsoft plans to address in future updates. Fixes for shared mailbox wrapper messages and delegated mailbox availability in hybrid environments are also included. Microsoft strongly urges customers to apply the update promptly to mitigate the mailbox access risk and ensure the continued health of their mail services.