Microsoft Rushes Urgent Exchange Server Patch for Critical Email Vulnerability

October 5, 2026
Microsoft Rushes Urgent Exchange Server Patch for Critical Email Vulnerability
  • Microsoft issued an out-of-band security update for Exchange Server to fix a high-severity vulnerability, CVE-2026-96940, which could let authenticated attackers read emails and attachments across mailboxes within the same organization but does not allow cross-tenant access.

  • The urgent update patches a privilege-escalation flaw (CVE-2026-96940) with a CVSS score of 8.8, affecting attackers who could access multiple mailboxes without bypassing tenant boundaries.

  • The update brings fixes but also side effects, including HTTP 500 errors in calendar apps from published calendars and a potential ContentEngine deadlock due to missing Korean word-break rules, with Microsoft planning future fixes.

  • Microsoft described the release as unusually timed, noting the update went out ahead of schedule without a disclosed reason.

  • Customers are advised to review deployment guidance and apply the September 2026 v2 update across all Exchange Servers and management tools to maintain compatibility.

  • In hybrid environments, Microsoft has patched cloud servers, while on-premises servers require admins to apply the updates themselves; the update is also recommended for Exchange instances used solely as management tools.

  • The patch is available for Exchange SE RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23, with older servers needing ESU Phase 2 to receive fixes.

  • On-premises versions include Subscription RTM, Exchange Server 2019 CU14/CU15, and Exchange Server 2016 CU23.

  • The rollout featured a muddled sequence, with a related service-side fix for Exchange Online arriving late and a KB article explaining the update content not being immediately available, later acknowledged by Microsoft.

  • Additional fixes include preventing messages from shared mailboxes showing up in the sender’s mailbox and correcting delegated mailbox availability status in hybrid setups when using Graph API.

  • Readers are encouraged to subscribe to breaking-news alerts for updates on breaches, vulnerabilities, and cybersecurity threats.

  • CVE-2026-96940 was identified internally; Microsoft reports no known active exploitation but warns the flaw could be exploited consistently, urging admins to update promptly.

Summary based on 2 sources


Get a daily email with more Tech stories

More Stories