News Date: 2026-10-02
Microsoft has issued a second version of its September 2026 Exchange Server security updates after adding protection for CVE-2026-96940, a high-severity authorization vulnerability affecting on-premises deployments.
The flaw carries a CVSS score of 8.8 and requires an attacker to possess valid credentials. Successful exploitation can allow the intruder to elevate privileges across the network and obtain unauthorized access to other users' mailboxes within the same organization. Messages and attachments could consequently become available to an account that should not have permission to read them.
Why Authenticated Flaws Still Matter
The authentication requirement reduces exposure to anonymous internet attacks, but it should not be mistaken for a strong protective boundary. Phishing, password reuse, information-stealing malware and compromised service accounts routinely provide criminals with valid Exchange credentials.
Once inside, an attacker could use the vulnerability to move beyond the original mailbox and collect sensitive executive communications, legal correspondence, financial records or password-reset messages. Email also contains valuable intelligence that can support more convincing impersonation and business email compromise attacks.
Microsoft says it discovered the vulnerability internally and has not identified active exploitation. The company nevertheless classified exploitation as more likely, making rapid remediation important for organizations operating affected servers.
Who Needs to Act
The affected products include Exchange Server Subscription Edition RTM and specific Exchange Server 2016 and 2019 cumulative updates. Access to new fixes for the older editions may depend on enrollment in Microsoft's Extended Security Update program because those products are outside normal support.
Exchange Online has received a service-side correction, so cloud-only customers do not need to deploy this server update. Hybrid organizations must still examine any on-premises Exchange servers and management-tools workstations remaining in their environment.
Defensive Priorities
- Install the revised Exchange security update on every eligible server.
- Verify deployment with the Exchange Server Health Checker.
- Reacquire updated compliance metadata if using the affected offline Scan Cab.
- Review mailbox access logs for unusual cross-user activity.
- Disable dormant accounts and investigate recent credential compromises.
In my view, the unusual out-of-band release sequence is itself a reason to check update status carefully. Administrators who deployed the original September package may reasonably assume they are protected, even though the revised release contains additional security coverage. Patch verification, not simply patch deployment, is the essential control in this situation.
