If you still run Exchange on your own servers, one phished employee login may be all it takes to read someone else’s mail. Microsoft shipped an out-of-band fix on Friday, October 2, for a flaw that lets any authenticated user open other mailboxes in the same organization, attachments included. Exchange Online is already fixed. Your on-prem servers are not, and that includes any that already installed September’s update.
One ordinary login, and the CFO’s inbox is readable. Exchange Online is fixed. Your server is not.
What happened
Microsoft published CVE-2026-96940 on October 2, 2026, outside the normal Patch Tuesday cycle. It describes the bug as “weak authorization in Microsoft Exchange Server” that lets an authenticated attacker elevate privileges over a network. In practice, an attacker with any mailbox account in the organization can gain access to other users’ mailboxes and read their messages and attachments. Microsoft says it does not cross tenant boundaries. The score is CVSS 8.8.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
The fix comes as a reissued package, the “September 2026 V2” Security Updates. The Exchange Server team says the only difference from the original September release is the addition of CVE-2026-96940. It also says this update “was published ahead of its intended schedule” and asks customers to apply it at the earliest opportunity. Microsoft found the flaw internally, credits researcher Jan Mitchell, and says it is not aware of active exploitation. It still rates the bug “Exploitation More Likely.”
Microsoft pushed a related service-side fix to Exchange Online late last week, so cloud-only tenants have nothing to do. Hybrid organizations still have to patch the Exchange servers they keep for management.
Why it matters
Mailbox-to-mailbox access is what business email compromise crews want: invoices, legal threads, password resets, board decks. The precondition is only “has an account.” That is any phished user, any sprayed password, any contractor account nobody disabled. Microsoft has not said which Exchange component is involved, so do not count on a WAF rule or a disabled protocol to cover it. The update is the control.
There is a second clock for Exchange 2016 and 2019. Both are out of support. Only organizations enrolled in the Period 2 Extended Security Update program can download these fixes, and Microsoft says that program covers updates released through the end of October 2026. If you are on 2016 or 2019 without ESU, there is no package for you. The way out is Exchange Server Subscription Edition.
What to do first
- Run Microsoft’s Exchange Server Health Checker (
HealthChecker.ps1) across the organization to see which servers are missing the V2 Security Update. - Install the V2 update that matches each server’s cumulative update: Exchange SE RTM, 2019 CU15, 2019 CU14, or 2016 CU23. Security Updates are cumulative, so you do not need to stack older ones first.
- Patch every Exchange server, including hybrid “management only” boxes, plus every server or workstation running the Exchange Management Tools. Microsoft says the management-only servers still need it.
- Reboot, then confirm all Exchange services started. Microsoft says services left disabled usually mean the install was interrupted.
- If you are on 2016 or 2019 without Period 2 ESU, escalate today: you cannot get this fix, and the migration to Exchange SE is now a security item, not a roadmap item.
- Expect two known issues from the September packages: published calendar (.ics) links can return HTTP 500, and environments with Korean-language mail can hit a ContentEngine deadlock.
Forward this
If you own email, or you own the budget for it: any employee account on our on-prem Exchange servers can currently be used to read other people’s mailboxes until we install Microsoft’s October 2 update (“September 2026 V2”). Exchange Online is already fixed. On-prem and hybrid management servers need the update this week. If we are on Exchange 2016 or 2019 without the extended-support contract, we cannot get this fix at all, and moving to Exchange SE needs a date.
Details
- CVE: CVE-2026-96940, Microsoft Exchange Server elevation of privilege (weak authorization). CVSS 3.1 8.8 (AV:N/AC:L/PR:L/UI:N). Same-organization mailbox read; no cross-tenant access.
- Status: Found internally. Microsoft: not publicly disclosed, not exploited, “Exploitation More Likely.” Not in CISA’s KEV catalog as of October 5, 2026.
- Released: October 2, 2026 (out of band), as the September 2026 V2 Security Updates.
- Fixed builds (Sep26SUv2): Exchange SE RTM 15.2.2562.53; Exchange 2019 CU15 15.2.1748.53; Exchange 2019 CU14 15.2.1544.48; Exchange 2016 CU23 15.1.2507.75.
- Still exposed (original Sep26SU, September 8): 15.2.2562.49, 15.2.1748.51, 15.2.1544.46, 15.1.2507.73.
- Packages: KB5129955 (SE RTM), KB5129956 (2019 CU15), KB5129957 (2019 CU14), KB5129958 (2016 CU23).
- Exchange 2016 / 2019: Out of support. Fixes only for Period 2 ESU customers; Microsoft says that program covers security updates until the end of October 2026.
- Exchange Online: Service-side fix already deployed. No customer action.
Hunt / verify
Get-ExchangeServeronly shows the CU level. To see the Security Update build, check the file version ofExSetup.exeon each server:Get-Command Exsetup.exe | ForEach-Object {$_.FileVersionInfo}.- Compare against the V2 builds above. A server on 15.2.2562.49, 15.2.1748.51, 15.2.1544.46 or 15.1.2507.73 has the original September update and is still exposed.
- Microsoft has published no indicators for this bug. As a starting point, if mailbox audit logging is on, review recent non-owner access to executive, legal and finance mailboxes and look for access that does not match a known delegate or admin.
- Treat any account flagged for phishing or password spraying in the last month as a candidate for mailbox access it should not have had.
Slack paste: On-prem Exchange: install the September 2026 V2 Security Update (released Oct 2) on every Exchange server and Management Tools host. Any authenticated user can read other mailboxes until then. Original Sept SU does not include the fix. Exchange Online already fixed. 2016/2019 need Period 2 ESU. CVE-2026-96940.
Sources
- https://learn.microsoft.com/en-us/exchange/new-features/build-numbers-and-release-dates
- https://support.microsoft.com/en-us/servicing/exchange/server/update/2026/5129957
- https://techcommunity.microsoft.com/blog/exchange/released-september-2026-exchange-server-security-updates/4554411
- https://www.helpnetsecurity.com/2026/10/05/exchange-server-vulnerability-cve-2026-96940/
- https://thehackernews.com/2026/10/microsoft-exchange-flaw-lets.html
- https://securityonline.info/exchange-server-security-updates-september-2026-v2/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://cybersecuretoday.com/article/microsoft-exchange-server-mailbox-access-privilege-escalation-cve-2026-96940
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.