Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Releases Critical Exchange Update for Security Flaw

Microsoft Releases Critical Exchange Update for Security Flaw

Posted on October 3, 2026 By CWS

Microsoft has issued a critical update for Exchange Server in September 2026 to address a significant security flaw identified as CVE-2026-96940. This vulnerability allows authenticated attackers to access other users’ mailboxes within the same organization, posing a serious risk to businesses utilizing on-premises Exchange servers.

Understanding the Security Vulnerability

The identified vulnerability results from weak authorization mechanisms, enabling attackers with authenticated access to escalate their privileges within a network. Classified with a CVSS score of 8.8, this flaw does not require any user interaction, unlike other vulnerabilities that depend on opening malicious files. Importantly, the exploit does not cross tenant boundaries, limiting its scope to the affected organization.

Microsoft’s internal teams discovered the vulnerability, and there are no reports of active exploitation at this time. The updates were released ahead of schedule, which may have caused some initial documentation gaps.

Details of the Updated Release

The September 2026 V2 release enhances protection by addressing CVE-2026-96940, supplementing the earlier September security updates. Organizations that applied the previous update should reassess their systems to ensure coverage by this latest patch.

These updates are available for various versions, including Exchange Server Subscription Edition RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23. Administrators need to choose the appropriate package for their specific version and cumulative update.

This issue is distinct from CVE-2026-62911, an earlier vulnerability involving an authentication relay attack path. It is vital not to conflate the two, as there is no evidence of an exploit for CVE-2026-96940 from prior research.

Support and Recommendations

Microsoft’s support for Exchange Server 2016 and 2019 has ended, with patches available only through the Period 2 Extended Security Update program, covering May to October 2026. This program requires a separate purchase, as no further extensions will be available beyond October. Organizations lacking this support should transition to the Exchange Server Subscription Edition to maintain security updates.

While Exchange Online customers are safeguarded against these vulnerabilities, those using hybrid deployments must update on-premises servers, including those solely for management purposes. Additionally, machines running Exchange Management Tools require these updates.

Microsoft advises using the Exchange Server Health Checker script to detect missing cumulative updates and manual actions. The Exchange Update Wizard helps plan the appropriate upgrade path. Following updates, administrators should restart servers, verify service functionality, and rerun Health Checker to ensure all steps are completed.

The release notes some known issues, such as HTTP 500 errors with calendar files and ContentEngine deadlocks affecting Korean language emails. Microsoft plans to resolve these in future updates. Other fixes include improvements for shared mailbox wrappers and delegated mailbox availability in hybrid setups.

Organizations are urged to follow deployment guidance and apply the update promptly to mitigate the mailbox access vulnerability while ensuring mail services remain operational post-patching.

Cyber Security News Tags:business technology, CVE-2026-96940, Cybersecurity, email security, Exchange Online, Exchange Server, hybrid deployments, IT management, IT security, Microsoft, on-premises server, patch management, security update, software update, Vulnerability

Post navigation

Previous Post: MI5 Warns of China’s Influence on UK Academics
Next Post: Warlock Group Targets SharePoint Flaws for Ransomware Attacks

Related Posts

Multiple PHP Vulnerabilities Allow SQL Injection & DoS Attacks Multiple PHP Vulnerabilities Allow SQL Injection & DoS Attacks Cyber Security News
Fake Claude Campaign Utilizes PlugX-Like DLL Sideloading Fake Claude Campaign Utilizes PlugX-Like DLL Sideloading Cyber Security News
Beware of Fake WinRAR Website That Delivers Malware with WinRAR Installer Beware of Fake WinRAR Website That Delivers Malware with WinRAR Installer Cyber Security News
Microsoft Enhances Teams for iOS and Android Microsoft Enhances Teams for iOS and Android Cyber Security News
Ransomware Attack on Phone Repair and Insurance Company Cause Millions in Damage Ransomware Attack on Phone Repair and Insurance Company Cause Millions in Damage Cyber Security News
Microsoft Teams Outage: Desktop Client Update Rollback Efforts Microsoft Teams Outage: Desktop Client Update Rollback Efforts Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Addressing Cybersecurity in an Era of Connected Vehicles
  • Warlock Group Targets SharePoint Flaws for Ransomware Attacks
  • Microsoft Releases Critical Exchange Update for Security Flaw
  • MI5 Warns of China’s Influence on UK Academics
  • Doxx.net Secures $38 Million for AI Safety Platform

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Addressing Cybersecurity in an Era of Connected Vehicles
  • Warlock Group Targets SharePoint Flaws for Ransomware Attacks
  • Microsoft Releases Critical Exchange Update for Security Flaw
  • MI5 Warns of China’s Influence on UK Academics
  • Doxx.net Secures $38 Million for AI Safety Platform

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark