Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
On October 2, 2026, Microsoft released an out-of-band update for Exchange Server that incorporates the fix for CVE-2026-96940, a privilege-escalation vulnerability rated CVSS 8.8. The release, labeled September 2026 V2, arrived ahead of its planned schedule with initially incomplete documentation, creating confusion among system administrators. The flaw allows an authenticated attacker with basic privileges to access other users' mailboxes within the same organization, without user interaction and over the network.
- CVE-2026-96940 has a CVSS 3.1 score of 8.8 (HIGH): network vector, low authenticated privileges, no user interaction, high impact on confidentiality, integrity, and availability.
- Microsoft classified the vulnerability as "Exploitation More Likely": no active exploits are known at the time of publication, but the likelihood of weaponization is considered high.
- The update was released ahead of the regular cycle: the Exchange Team later confirmed on TechCommunity that the V2 specifically adds this CVE to the original September package.
- Exchange Server 2016 and 2019 require enrollment in the ESU Period 2 program (expiring October 2026) to receive the patch: organizations without extended support remain exposed.
The Mechanism: Weak Authorization and Access to Other Mailboxes
The vulnerability resides in an authorization flaw in Microsoft Exchange Server code. An already-authenticated attacker with limited privileges exploits this weakness to elevate their rights over the network, gaining unauthorized access to other users' mailboxes within the same organization. The impact declared by Microsoft includes reading email messages and attachments. Access does not cross tenant boundaries: according to the official advisory, it is not possible to compromise mailboxes of external organizations.
The CVSS 3.1 assigned by the official CVE.org record is 8.8, with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The UI:N (User Interaction: None) parameter is particularly relevant to the risk profile: exploitation requires no action by the victim. At the time of publication, exploit code maturity is E:U (Unproven): no public exploit is available.
The Early Release and Documentation Confusion
The update emerged as a revision of the September 2026 security package. The Exchange Team's TechCommunity blog, the official contextual source, clarified that "This specific update, which adds CVE-2026-96940, was published ahead of its intended schedule." Initial documentation was not fully available at first publication, creating an information gap that forced administrators to navigate fragmented advisories and updated release notes.
The phenomenon is not isolated in the recent Exchange Server lifecycle. Operational pressure on the development team manifests in compressed releases, release notes that integrate post-publication fixes, and growing complexity in tracking builds for on-premises environments. The distinction between Exchange Online, where the service-side fix is already deployed with no customer action required, and on-premises instances widens the operational divide.
What to Do Now
Microsoft recommends installing the September 2026 V2 update on all Exchange servers and all workstations running Exchange Management Tools, as reported by HelpNetSecurity citing official team guidance. The explicit recommendation aims to ensure compatibility between management clients and servers.
Priority actions for administrators are fourfold. First: verify the installed build against the corrected versions listed in the CVE.org record — Exchange 2016 CU23 updated to build 15.01.2507.075 or later; Exchange 2019 CU14 to 15.02.1544.048 or later; Exchange 2019 CU15 to 15.02.1748.053 or later; Exchange SE RTM to 15.02.2562.053 or later. Second: confirm ESU Period 2 enrollment status for Exchange 2016/2019 installations, a necessary condition for update access. Third: apply the patch to all servers in the organization, not only those directly exposed to the Internet, since the attack vector is network-based and internal authentication is sufficient. Fourth: plan deployment accounting for known issues documented by the Exchange Team, including HTTP 500 errors on calendars and ContentEngine deadlocks in Korean-language environments.
The ESU Knot and the October 2026 Deadline
The situation for Exchange Server 2016 and 2019 is critical on the timeline. Both products are out of standard support; security updates released between May and October 2026 are reserved exclusively for customers enrolled in Period 2 of the Extended Security Update program. The hard deadline is October 2026. Organizations that have not completed migration to Exchange Online or Exchange Server Subscription Edition, and have not purchased the extension, find themselves in a structural risk condition: they cannot patch vulnerabilities classified "More Likely" with CVSS 8.8.
The source does not specify the exact nature of the risk for hybrid environments where unpatched on-premises servers coexist with Exchange Online tenants. The dossier also does not document alternative mitigations for organizations not covered by ESU.
"We recommend that customers review the deployment guidance and apply the [September 2026 v2] update at the earliest opportunity"
— Exchange Server Team
Why the 'More Likely' Class Changes the Risk Calculation
Microsoft's "Exploitation More Likely" assessment is not a bureaucratic formality. It designates vulnerabilities for which the vendor believes functional exploit code is likely to be developed, based on historical patterns, technical complexity of the flaw, and target attractiveness. In a product like Exchange Server — a historic entry point for intelligence and cybercrime attacks, with a well-mapped attack surface — this classification signals that reaction time must be measured in days, not weeks.
The contrast between Microsoft's statement of no active exploits and the "More Likely" exploitability class defines the defenders' maneuvering room: there is no indication of ongoing compromise, but the condition is unstable. The operational pressure that drove the early release suggests the internal discovery required intervention incompatible with the normal Patch Tuesday window.
Remaining Uncertainties
The dossier presents significant limits. The exact date of internal vulnerability discovery is unknown. The specific reason for the early release is not declared by Microsoft. No specific indicators of compromise emerge to detect exploitation attempts. The resolution timeline for known issues associated with the update is not documented. The precise relationship with CVE-2026-62911, another recent Exchange flaw, is explicitly one of separation: the two vulnerabilities are distinct, as Cryptika underscores.
For administrators, the absence of known active exploits does not lower the priority: the combination of CVSS 8.8, no user interaction, and "More Likely" classification places CVE-2026-96940 in the top tier of patches to apply urgently.
Sources
- https://www.helpnetsecurity.com/2026/10/05/exchange-server-vulnerability-cve-2026-96940/
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940
- https://www.cryptika.com/microsoft-pushes-new-exchange-v2-update-after-discovering-new-security-flaw/
- https://www.cve.org/CVERecord?id=CVE-2026-96940
- https://techcommunity.microsoft.com/blog/exchange/released-september-2026-v2-exchange-server-security-updates/4561718
Information verified against cited sources and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.