International Edition
Latest News
Technology

Microsoft Issues V2 September 2026 Update for High-Severity Exchange Server Flaw (CVE-2026-96940)

Microsoft Exchange Server CVE-2026-96940 Vulnerability Patch Released Microsoft has published an out-of-band security update addressing CVE-2026-96940, a high-severity elevation-of-privilege vulnerability affecting on-premises Microsoft Exchange Server deployments. While no active attacks are currently documented, Microsoft categorizes exploitation as "more…

Microsoft Security image

Microsoft Exchange Server CVE-2026-96940 Vulnerability Patch Released

Microsoft has published an out-of-band security update addressing CVE-2026-96940, a high-severity elevation-of-privilege vulnerability affecting on-premises Microsoft Exchange Server deployments. While no active attacks are currently documented, Microsoft categorizes exploitation as “more likely,” requiring administrators to deploy targeted patches immediately.

Flaw Lets Attackers Read Email Messages

Attackers can read email messages and attachments, though the flaw does not permit cross-tenant access. The vulnerability affects Exchange Server Subscription Edition alongside supported Exchange 2016 and Exchange 2019 builds still receiving security updates.

Administrators Must Deploy V2 September Security Updates

Administrators must deploy the V2 September 2026 security updates to remediate the risk, even if they previously installed initial September patches that lacked the fix. According to Microsoft, the specific update requirements and target builds include:

  • Microsoft Exchange Server 2016 Cumulative Update 23 (x64): Install KB5129958 to reach fixed build 15.01.2507.075.
  • Microsoft Exchange Server 2019 Cumulative Update 14 (x64): Install KB5129957 to reach fixed build 15.02.1544.048.
  • Microsoft Exchange Server 2019 Cumulative Update 15 (x64): Install KB5129956 to reach fixed build 15.02.1748.053.
  • Microsoft Exchange Server Subscription Edition RTM (x64): Install KB5129955 to reach fixed build 15.02.2562.053.

Exchange Online Versus On-Premises Deployment Impact

Cloud infrastructure remains unaffected by the vulnerability. Microsoft deployed a service-side mitigation for Exchange Online customers, meaning cloud tenants require no manual intervention. Conversely, hybrid and on-premises environments require explicit updates across all local Exchange servers, including management machines and systems running Exchange Management tools. Organizations running Exchange Server 2016 or 2019 must obtain fixes through Microsoft’s Period 2 Extended Security Update (ESU) program, which demands separate licensing.

Abstract illustration of connected devices separated by a protected security boundary
Photo: windowsforum.com

Frequently Asked Questions on CVE-2026-96940

Does CVE-2026-96940 allow attackers to compromise cross-tenant environments?

No, the vulnerability is strictly confined within the same organization. Attackers cannot use this flaw to access mailboxes across different tenant boundaries.

Are Exchange Online customers required to install KB5129955 or related updates?

No action is necessary for Exchange Online tenants because Microsoft has already applied a service-side mitigation to protect cloud-hosted infrastructure.

What licensing is required to secure older Exchange Server builds against this flaw?

Organizations operating Exchange Server 2016 or 2019 must enroll in Microsoft’s Period 2 Extended Security Update (ESU) program to receive the necessary patches.

About the author: Anika Shah - Technology

MSc in Computer Science, senior reporter. Anika focuses on AI ethics, cybersecurity, and emerging hardware—frequently moderating panels at CES and Web Summit. “Anika Shah decodes tech breakthroughs and startup disruption shaping tomorrow’s digital landscape.”