Microsoft Rushes Urgent Exchange Server Patch for Critical Email Vulnerability
October 5, 2026
Microsoft issued an out-of-band security update for Exchange Server to fix a high-severity vulnerability, CVE-2026-96940, which could let authenticated attackers read emails and attachments across mailboxes within the same organization but does not allow cross-tenant access.
The urgent update patches a privilege-escalation flaw (CVE-2026-96940) with a CVSS score of 8.8, affecting attackers who could access multiple mailboxes without bypassing tenant boundaries.
The update brings fixes but also side effects, including HTTP 500 errors in calendar apps from published calendars and a potential ContentEngine deadlock due to missing Korean word-break rules, with Microsoft planning future fixes.
Microsoft described the release as unusually timed, noting the update went out ahead of schedule without a disclosed reason.
Customers are advised to review deployment guidance and apply the September 2026 v2 update across all Exchange Servers and management tools to maintain compatibility.
In hybrid environments, Microsoft has patched cloud servers, while on-premises servers require admins to apply the updates themselves; the update is also recommended for Exchange instances used solely as management tools.
The patch is available for Exchange SE RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23, with older servers needing ESU Phase 2 to receive fixes.
On-premises versions include Subscription RTM, Exchange Server 2019 CU14/CU15, and Exchange Server 2016 CU23.
The rollout featured a muddled sequence, with a related service-side fix for Exchange Online arriving late and a KB article explaining the update content not being immediately available, later acknowledged by Microsoft.
Additional fixes include preventing messages from shared mailboxes showing up in the sender’s mailbox and correcting delegated mailbox availability status in hybrid setups when using Graph API.
Readers are encouraged to subscribe to breaking-news alerts for updates on breaches, vulnerabilities, and cybersecurity threats.
CVE-2026-96940 was identified internally; Microsoft reports no known active exploitation but warns the flaw could be exploited consistently, urging admins to update promptly.
Summary based on 2 sources
Get a daily email with more Tech stories
Sources

Help Net Security • Oct 5, 2026
Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940)