On-premises Microsoft Exchange Server has a privilege-escalation flaw that lets any authenticated user read other people's mail. On 2 October 2026, outside the Patch Tuesday cycle, Microsoft published CVE-2026-96940. It also reissued its September Exchange Security Updates as "September 2026 v2" to fix the flaw. The original September SUs, released on 8 September, do not contain the fix. Every Exchange Server SE, 2019 and 2016 server, and every workstation running the Exchange Management Tools, needs the v2 package. Microsoft rates the flaw "Exploitation More Likely". Exchange Online customers do not need to do anything.
What CVE-2026-96940 Does
MSRC's description is short: "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network." The flaw is classed as CWE-1390 (Weak Authentication), with a CVSS 3.1 base score of 8.8 and a temporal score of 7.7. The vector is AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. That means it is exploitable over the network, with low complexity and no user interaction. The attacker needs only a low-privileged account.
MSRC's FAQ explains the practical impact:
"An authenticated attacker who successfully exploited this vulnerability could gain unauthorized access to other users' mailboxes within the same organization and read email messages and attachments. The vulnerability does not allow access across tenant boundaries."
In other words, any mailbox-enabled account in the organisation is enough to open the mailboxes of executives, legal teams or finance staff. That includes an account taken over through phishing, password spraying or token theft. Microsoft has not said which Exchange component, protocol or endpoint is involved, and we will not speculate.
Why There Is a "v2" Update
The Exchange team's release post sets out what changed: "The difference between the original September 2026 Security Update release and this V2 release is an addition of CVE-2026-96940." It also explains the unusual timing: "This specific update, which adds CVE-2026-96940, was published ahead of its intended schedule. We recommend that customers review the deployment guidance and apply the update at the earliest opportunity."
The v2 KB articles replace earlier packages. For Exchange Server SE RTM, KB5129955 says it replaces the 11 August 2026 update (KB5121573). KB5129955 lists nine CVEs: CVE-2026-96940 plus eight others.
Exploitation Status
MSRC marks CVE-2026-96940 as not publicly disclosed and not exploited. The Exchange team says: "We identified the vulnerability internally and are not aware of active exploitation." The flaw is not in CISA's Known Exploited Vulnerabilities catalog. Microsoft still assigns it the "Exploitation More Likely" rating. Combined with an attack that needs only a low-privileged account, that is enough to treat this as an urgent patch rather than routine maintenance. On-premises Exchange has long been a favoured target for intruders.
Affected and Fixed Exchange Builds
| Exchange version | Original Sep26SU build (8 Sept, still vulnerable) | Sep26SUv2 build (2 Oct, fixed) | KB |
|---|---|---|---|
| Exchange Server SE RTM | 15.02.2562.049 | 15.02.2562.053 | KB5129955 |
| Exchange Server 2019 CU15 | 15.02.1748.051 | 15.02.1748.053 | KB5129956 |
| Exchange Server 2019 CU14 | 15.02.1544.046 | 15.02.1544.048 | KB5129957 |
| Exchange Server 2016 CU23 | 15.01.2507.073 | 15.01.2507.075 | KB5129958 |
Exchange 2016 and 2019 are out of support. Microsoft says their updates are available only to organisations enrolled in the Period 2 Extended Security Update (ESU) programme, which covers updates released between May and October 2026. Organisations without ESU cannot get this fix for 2016 or 2019. Microsoft's advice for them is to move to Exchange Server SE.
Defensive Playbook: Patch, Verify, Review
1. Check the installed build correctly
Microsoft's build-number documentation notes that Get-ExchangeServer shows only the cumulative update level, not the installed SU. Use it to confirm which CU each server runs:
# Exchange Management Shell — shows CU level only, not SU/HU
Get-ExchangeServer | Format-List Name,Edition,AdminDisplayVersion
To confirm the SU build, check the file version of ExSetup.exe on each server. Compare it against the v2 builds in the table above.
# Run on each Exchange server — shows the full build including SU
Get-Command Exsetup.exe | ForEach-Object {$_.FileVersionInfo}
If a server reports 15.02.2562.049, 15.02.1748.051, 15.02.1544.046 or 15.01.2507.073, it has the original September SU and is still exposed.
2. Run Microsoft's Exchange Health Checker
Both the Exchange team's post and the KB articles point admins to the Exchange Server Health Checker (HealthChecker.ps1 from Microsoft's CSS-Exchange project). It inventories the estate and flags servers that are behind on CUs, SUs or manual actions. The documented usage includes:
# Single server
.HealthChecker.ps1 -Server EXCH1
# Vulnerability-focused report
.HealthChecker.ps1 -VulnerabilityReport
# Org-wide HTML report after collecting data
.HealthChecker.ps1 -BuildHtmlServersReport
3. Deploy the v2 SU everywhere
- Install the v2 SU that matches each server's CU (KB5129955 to KB5129958). SUs are cumulative, so servers on a supported CU do not need older SUs installed first.
- Install the SU on all Exchange servers, including hybrid management servers and machines that run only the Exchange Management Tools. Microsoft says this is required "even if they are used only for management purposes".
- Reboot, then confirm that all Exchange services have started. Microsoft notes that services left disabled usually mean the installation was interrupted.
- Check the known issues. Microsoft lists published calendar (.ics) feeds returning HTTP 500, and a ContentEngine deadlock in environments with Korean-language mail.
4. Review mailbox access (starting point)
Microsoft has published no indicators for CVE-2026-96940. It is also unknown whether abuse would produce the same audit records as normal delegated access. As a starting point, review recent non-owner access to high-value mailboxes, assuming mailbox audit logging was enabled. Look closely at accesses that do not match known delegate or admin assignments:
# Starting point only — requires mailbox audit logging to be enabled
Search-MailboxAuditLog -Identity "cfo@contoso.com" -LogonTypes Delegate,Admin -ShowDetails -StartDate (Get-Date).AddDays(-30) |
Select-Object LastAccessed,LogonType,LogonUserDisplayName,Operation,ClientIPAddress
Exchange Online tenants are already protected by Microsoft's service-side fix. Hybrid organisations still have to patch their on-premises servers.



