Exchange CVE-2026-96940 (CVSS 8.8): Sep 2026 V2 SU — auth'd mailbox access same org; install V2 even if Sep SU already applied
Microsoft re-released the September 2026 Exchange Server security updates on 2 October 2026 as V2 solely to add CVE-2026-96940 (CVSS 3.1 8.8; AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H): weak authorisation allowing an authenticated attacker to elevate privileges over the network and gain unauthorised access to other users’ mailboxes (messages and attachments) within the same organisation — not across tenant boundaries. Microsoft discovered the flaw internally; MSRC lists it as not publicly disclosed and not exploited, with exploitation more likely. Anyone who installed the original September SU still needs the V2 package. Fixed builds/KBs (Security Update Guide / coverage): Exchange Server Subscription Edition RTM KB5129955 build 15.02.2562.053; Exchange 2019 CU15 KB5129956 15.02.1748.053; Exchange 2019 CU14 KB5129957 15.02.1544.048; Exchange 2016 CU23 KB5129958 15.01.2507.075. Exchange Online already protected; hybrid and Exchange Management Tools hosts must still patch on-prem. 2016/2019 fixes require Period 2 ESU (May–Oct 2026); otherwise migrate to SE. Distinct from desk card cve-2026-62911 (Aug auth-bypass / Shadowserver). Primary: MSRC CVE-2026-96940; wire: CybersecurityNews 3 Oct.
- Product
- Microsoft Exchange Server (on-premises SE / 2019 / 2016); Exchange Management Tools
- Versions
- SE RTM before 15.02.2562.053; 2019 CU15 before 15.02.1748.053; 2019 CU14 before 15.02.1544.048; 2016 CU23 before 15.01.2507.075. Fixed: Sep 2026 V2 SUs KB5129955–5129958 as above. 2016/2019: Period 2 ESU only.
- CVSS
CVE-2026-96940CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H- Exploited in Australia?
- unknown
- Patch to
- Install September 2026 V2 SU for your CU on every Exchange server and every Management Tools host; reboot; confirm services; re-run Health Checker. If auth cert changed post-SU, re-run Hybrid Configuration Wizard. Without Period 2 ESU on 2016/2019: migrate to Exchange SE. Exchange Online-only: no action.
Primary: Microsoft MSRC — CVE-2026-96940 Exchange Server Elevation of Privilege (2 Oct 2026) · Vendor: Microsoft Exchange Team — September 2026 Exchange Server Security Updates (V2 reissue 2 Oct) · CVE: CVE-2026-96940, CVE-2026-62911 · CybersecurityNews — Microsoft pushes Exchange V2 update for CVE-2026-96940 (3 Oct 2026)
