Microsoft Exchange Server CVE-2026-96940 Vulnerability Patch Released
Microsoft has published an out-of-band security update addressing CVE-2026-96940, a high-severity elevation-of-privilege vulnerability affecting on-premises Microsoft Exchange Server deployments. While no active attacks are currently documented, Microsoft categorizes exploitation as “more likely,” requiring administrators to deploy targeted patches immediately.
Flaw Lets Attackers Read Email Messages
Attackers can read email messages and attachments, though the flaw does not permit cross-tenant access. The vulnerability affects Exchange Server Subscription Edition alongside supported Exchange 2016 and Exchange 2019 builds still receiving security updates.
Administrators Must Deploy V2 September Security Updates
Administrators must deploy the V2 September 2026 security updates to remediate the risk, even if they previously installed initial September patches that lacked the fix. According to Microsoft, the specific update requirements and target builds include:
- Microsoft Exchange Server 2016 Cumulative Update 23 (x64): Install KB5129958 to reach fixed build 15.01.2507.075.
- Microsoft Exchange Server 2019 Cumulative Update 14 (x64): Install KB5129957 to reach fixed build 15.02.1544.048.
- Microsoft Exchange Server 2019 Cumulative Update 15 (x64): Install KB5129956 to reach fixed build 15.02.1748.053.
- Microsoft Exchange Server Subscription Edition RTM (x64): Install KB5129955 to reach fixed build 15.02.2562.053.
Exchange Online Versus On-Premises Deployment Impact
Cloud infrastructure remains unaffected by the vulnerability. Microsoft deployed a service-side mitigation for Exchange Online customers, meaning cloud tenants require no manual intervention. Conversely, hybrid and on-premises environments require explicit updates across all local Exchange servers, including management machines and systems running Exchange Management tools. Organizations running Exchange Server 2016 or 2019 must obtain fixes through Microsoft’s Period 2 Extended Security Update (ESU) program, which demands separate licensing.
Frequently Asked Questions on CVE-2026-96940
Does CVE-2026-96940 allow attackers to compromise cross-tenant environments?
No, the vulnerability is strictly confined within the same organization. Attackers cannot use this flaw to access mailboxes across different tenant boundaries.
Are Exchange Online customers required to install KB5129955 or related updates?
No action is necessary for Exchange Online tenants because Microsoft has already applied a service-side mitigation to protect cloud-hosted infrastructure.
What licensing is required to secure older Exchange Server builds against this flaw?
Organizations operating Exchange Server 2016 or 2019 must enroll in Microsoft’s Period 2 Extended Security Update (ESU) program to receive the necessary patches.