Exchange Server CVE-2026-96940 gets out-of-band patch

Exchange Server CVE-2026-96940 gets out-of-band patch

Microsoft has released an out-of-band security update for on-premises Exchange Server. It fixes CVE-2026-96940, a high-severity flaw that could let an authenticated attacker read the emails and attachments of other users in the same organization.

The company says the bug "does not allow access across tenant boundaries." An attacker would therefore be limited to mailboxes within the organization they already have access to. They would not be able to reach other customers' data.

Microsoft found the vulnerability internally. The Exchange Server Team says it is "not aware of active exploitation." Even so, Microsoft considers the flaw one that could be exploited consistently. It also notes that this class of vulnerability has been exploited before, and it is urging Exchange administrators to patch soon rather than wait for a regular maintenance window.

Which versions are affected

The update covers on-prem servers running:

  • Exchange Server Subscription Edition RTM
  • Exchange Server 2019 cumulative updates (CUs) 14 and 15
  • Exchange Server 2016 cumulative update 23

Microsoft refers to the release as the September 2026 v2 update.

"We recommend that customers review the deployment guidance and apply the [September 2026 v2] update at the earliest opportunity," the Exchange Server Team said.

The team also pointed to a step that is easy to miss. The update should go on every Exchange server, and also on every server and workstation that runs the Exchange Management Tools.

"Our recommendation is to install SUs on all Exchange Servers and all servers and workstations running the Exchange Management Tools to ensure compatibility between management tools clients and servers," the team said. SU is Microsoft's short form for security update.

A confusing rollout

The release did not go smoothly. Late last week, Microsoft applied a related service-side fix to Exchange Online, its cloud-hosted email service. Because the fix ran on Microsoft's own infrastructure, cloud customers did not have to do anything.

The updates did not come with a KB article at first. KB articles are the Knowledge Base documents Microsoft normally publishes to explain what a patch changes. Without one, customers saw security updates appear with no explanation of what they addressed.

Microsoft later acknowledged the problem. The Exchange Server Team said the release sequence for this update was unusual because it had been published earlier than planned. The team did not say why the update went out ahead of schedule.

For on-prem administrators, this means the cloud side was fixed first and the self-managed side followed. In the meantime, details about the issue were already circulating.

What admins should do

The advice is simple:

  1. Identify which Exchange Server version and CU each server runs.
  2. Read Microsoft's deployment guidance for the September 2026 v2 update.
  3. Install the update on all Exchange servers.
  4. Install it on any other servers and workstations that run the Exchange Management Tools, so management clients and servers stay compatible.

Organizations still on CUs older than those listed above will need to move to a supported CU before they can apply the fix.

Our Take

No exploitation has been reported, but this patch should not be pushed to the back of the queue. Microsoft itself says the flaw can be exploited reliably and that similar bugs have been exploited before. Read access to colleagues' mailboxes is valuable to an attacker who already has a foothold, whether through a phished account or a compromised insider. It could expose executive email, contracts or password reset messages without any further intrusion.

Self-hosted email and collaboration servers have been popular targets recently. We have covered a Zimbra flaw exploited before disclosure and a FortiMail zero-day. Ransomware operators have also been abusing SharePoint flaws in on-prem Microsoft environments. Against that backdrop, attackers are likely to study Exchange patches closely.

The muddled rollout is a concern too. Fixes that appear before their documentation make it harder for defenders to prioritize. It is worth watching whether Microsoft explains the early release, and whether exploit details for CVE-2026-96940 surface now that the fix is public.