Microsoft has issued a critical update for Exchange Server in September 2026 to address a significant security flaw identified as CVE-2026-96940. This vulnerability allows authenticated attackers to access other users’ mailboxes within the same organization, posing a serious risk to businesses utilizing on-premises Exchange servers.
Understanding the Security Vulnerability
The identified vulnerability results from weak authorization mechanisms, enabling attackers with authenticated access to escalate their privileges within a network. Classified with a CVSS score of 8.8, this flaw does not require any user interaction, unlike other vulnerabilities that depend on opening malicious files. Importantly, the exploit does not cross tenant boundaries, limiting its scope to the affected organization.
Microsoft’s internal teams discovered the vulnerability, and there are no reports of active exploitation at this time. The updates were released ahead of schedule, which may have caused some initial documentation gaps.
Details of the Updated Release
The September 2026 V2 release enhances protection by addressing CVE-2026-96940, supplementing the earlier September security updates. Organizations that applied the previous update should reassess their systems to ensure coverage by this latest patch.
These updates are available for various versions, including Exchange Server Subscription Edition RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23. Administrators need to choose the appropriate package for their specific version and cumulative update.
This issue is distinct from CVE-2026-62911, an earlier vulnerability involving an authentication relay attack path. It is vital not to conflate the two, as there is no evidence of an exploit for CVE-2026-96940 from prior research.
Support and Recommendations
Microsoft’s support for Exchange Server 2016 and 2019 has ended, with patches available only through the Period 2 Extended Security Update program, covering May to October 2026. This program requires a separate purchase, as no further extensions will be available beyond October. Organizations lacking this support should transition to the Exchange Server Subscription Edition to maintain security updates.
While Exchange Online customers are safeguarded against these vulnerabilities, those using hybrid deployments must update on-premises servers, including those solely for management purposes. Additionally, machines running Exchange Management Tools require these updates.
Microsoft advises using the Exchange Server Health Checker script to detect missing cumulative updates and manual actions. The Exchange Update Wizard helps plan the appropriate upgrade path. Following updates, administrators should restart servers, verify service functionality, and rerun Health Checker to ensure all steps are completed.
The release notes some known issues, such as HTTP 500 errors with calendar files and ContentEngine deadlocks affecting Korean language emails. Microsoft plans to resolve these in future updates. Other fixes include improvements for shared mailbox wrappers and delegated mailbox availability in hybrid setups.
Organizations are urged to follow deployment guidance and apply the update promptly to mitigate the mailbox access vulnerability while ensuring mail services remain operational post-patching.
