7 October 2026 5 min read

Exchange Security Update September 2026 v2: Early Fix for CVE-2026-96940

On October 2, 2026, Microsoft released version 2 of the September SUs for Exchange SE, 2019, and 2016. It additionally closes CVE-2026-96940, an elevation-of-privilege vulnerability with CVSS 8.8 and an “Exploitation More Likely” assessment. Microsoft recommends installing v2 as soon as possible, including on servers with the first September SU.

Current version and all builds: Exchange build numbers

On October 2, 2026, Microsoft released Version 2 (v2) of the September security updates (SUs) for Exchange Server SE, Exchange 2019, and Exchange 2016. According to the announcement, the only difference from the first version of September 8 is that v2 additionally closes CVE-2026-96940. The vulnerability is neither publicly known nor being exploited; Microsoft found it internally. Two things are unusual: Microsoft says it released this update earlier than planned, and the Security Update Guide rates exploitation as “Exploitation More Likely.” The nine vulnerabilities in the first release, the fixed wrapper issue, and the known issues are described in the September SU article; this article covers what is new in v2.

Which Exchange versions have the update available

The October 2, 2026 v2 SUs are available for the following versions:

  • Exchange Server Subscription Edition (SE) RTM: KB5129955, Build 15.2.2562.53; publicly available.
  • Exchange Server 2019 CU15: KB5129956, Build 15.2.1748.53; only through the Period 2 ESU program.
  • Exchange Server 2019 CU14: KB5129957, Build 15.2.1544.48; only through Period 2 ESU.
  • Exchange Server 2016 CU23: KB5129958, Build 15.1.2507.75; only through Period 2 ESU.

The updates are CU-specific: the package for CU15 cannot be installed on CU14. Exchange 2016 and 2019 are out of support. According to the announcement FAQ, only organizations in the Period 2 ESU program, which runs from May through October 2026, receive updates released after May 2026 for these versions; Microsoft recommends that everyone else move to Exchange SE as soon as possible. For hybrid environments with outdated servers, Exchange Online transport enforcement is an additional consideration.

You can check whether your servers are already on the v2 build using the Exchange build numbers overview.

The vulnerability at a glance

CVETypeCVSS
CVE-2026-96940Elevation of Privilege8.8

Microsoft describes **CVE-2026-96940 as weak authorization in Exchange Server that lets an authenticated attacker elevate their privileges over the network. The CVSS vector lists low requirements: network-based attack, low complexity, an account with low privileges, and no user interaction. According to the Security Update Guide FAQ, a successful attacker gains unauthorized access to mailboxes of other users in the same organization and can read their email, including attachments; access remains limited to their own organization. Microsoft rates the vulnerability as Important, with a Temporal Score of 7.7.

The “Exploitation More Likely” assessment is the key difference from the nine CVEs in the first release, all of which Microsoft rated as “Exploitation Less Likely.” An attack starts with any valid user account, such as after a successful phishing attack. Microsoft has remediated Exchange Online server-side; no action is required there. Microsoft does not list a mitigation or workaround for servers without v2 (as of October 7, 2026).

The other CVEs in the v2 KB articles are the same as in the first release: CVE-2026-55007, CVE-2026-69355, CVE-2026-69356, CVE-2026-69361, CVE-2026-69375, CVE-2026-69378, CVE-2026-69382, and CVE-2026-69641. As with the September KBs, CVE-2026-69380 is absent, although the Security Update Guide also states that it is closed by the September SU.

Why there is a v2 and what you need to do

In the announcement FAQ, Microsoft answers the question about the unusual timing as follows: the update containing CVE-2026-96940 was released before its planned date, and Microsoft recommends reviewing the deployment guidance and installing the update at the earliest opportunity. Microsoft does not state why the date was brought forward.

This results in the following practical guidance:

  1. Servers with the September 8 SU (Builds 15.2.2562.49, 15.2.1748.51, 15.2.1544.46, 15.1.2507.73) are not protected against CVE-2026-96940. The Security Update Guide lists only the four v2 builds as fixes for this CVE. These servers need v2.

  2. Servers on an older build can install v2 directly. According to the FAQ, SUs are cumulative; anyone on a supported CU only installs the latest SU.

  3. Machines with the Exchange Management Tools and dedicated management servers also receive v2; Microsoft recommends this for all SUs, including in hybrid environments.

According to KB5129955, the installation file for Exchange SE is named ExchangeSubscriptionEdition-KB5129955-x64-en.exe; it is available from the Microsoft Update Catalog and the Download Center, where it is labeled “SU10V2.”

Known issues

The known issues from the first release also apply to v2. As of October 7, 2026:

Published calendars (.ics) return HTTP 500 to calendar applications (all versions). The issue has existed since the August SU and remains listed as a known issue in all four v2 KBs. Microsoft is still investigating it and describes a URL rewrite rule on the “Exchange Back End” site as a temporary workaround; the steps are available in Support article KB5126672 and in the September SU article. The rule must be configured on every server and, according to Microsoft, reviewed again after future updates.

ContentEngine deadlock due to missing Korean WordBreaker files (Exchange SE only). According to KB5130098, both releases are explicitly affected: Build 15.2.2562.49 and v2 Build 15.2.2562.53. Therefore, v2 does not fix the issue. Symptoms include missing search results, delayed mail delivery, and hung or disconnected Outlook or MAPI clients; according to the announcement, it affects organizations with email in Korean. The manual workaround (two rule files from SQL Server 2025 Express RTM, verification using an SHA256 hash) is in the Support article; Microsoft continues to investigate the issue.

Free/busy for delegated mailboxes in hybrid environments with a Graph API-only configuration (Exchange SE only). The Sources conflict here: the v2 announcement lists the issue among the resolved problems, KB5129955 still lists it as a known issue, and Support article KB5127092 reports the status “Microsoft is investigating this issue” without mentioning a fix. If you set the SettingOverride EnableRouteThroughMSGraphFeature described there as a workaround, remove it after installing v2 only after testing, until Microsoft publishes instructions for doing so.

Installation and follow-up

Microsoft lists the familiar process in its announcement: inventory systems with the Exchange Health Checker, determine the path with the Exchange Update Wizard when the CU build is outdated, restart the server after setup, and verify that all Exchange services have started. For errors during or after installation, Microsoft refers to the SetupAssist script. The Security Update Guide does not list a required restart for the v2 builds under CVE-2026-96940, but the announcement still recommends restarting after setup.

For hybrid environments, the FAQ states: if the auth certificate is changed after installing an SU, run the Hybrid Configuration Wizard again. On Windows Server 2025, installed Exchange SUs do not appear in Control Panel; Microsoft generally advises against uninstalling SUs and refers to a separate Support article for this case.

The following follow-up tasks from previous months remain outstanding if not yet completed: remove the wrapper SettingOverride DisableBlockSharedAndUserMailboxHeaders (see the September article) and check whether the CVE-2026-42897 mitigation (M2.1.0) is still active (see the July SU article).

Install v2 promptly on all Exchange servers and Exchange Management Tools machines, including those already running the September SU: only the v2 builds close CVE-2026-96940, a single compromised user account is enough to access other mailboxes, and Microsoft considers exploitation more likely than for all other September CVEs. Then use the Health Checker to verify the build level, check the WordBreaker issue on Exchange SE, and retain existing workarounds until Microsoft documents their removal. The ESU program for Exchange 2016 and 2019 ends in October 2026; after that, no further updates will be released for these versions.

Sources

  1. Released: September 2026 V2 Exchange Server Security Updates – Microsoft Community Hub

    Announcement of v2 from October 2, 2026, including the difference from the first release, the FAQ about the early release, known issues, resolved problems, and installation process (accessed through the Exchange Team Blog RSS feed).

    https://techcommunity.microsoft.com/t5/exchange-team-blog/released-september-2026-v2-exchange-server-security-updates/ba-p/4561718
  2. CVE-2026-96940 – Security Update Guide, Microsoft Security Response Center

    Type, CVSS 8.8/7.7 with vector, severity, exploitation assessment, FAQ, and the four v2 builds as fixes.

    https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940
  3. Description of version 2 of the security update for Microsoft Exchange Server Subscription Edition RTM October 2, 2026 (KB5129955) – Microsoft Support

    CVE list, known issues, resolved problems, and installation file for Exchange SE.

    https://support.microsoft.com/help/5129955
  4. Description of version 2 of the security update for Microsoft Exchange Server 2019 CU15 (KB5129956) – Microsoft Support

    KB article for Exchange 2019 CU15 with an ESU note.

    https://support.microsoft.com/help/5129956
  5. Description of version 2 of the security update for Microsoft Exchange Server 2019 CU14 (KB5129957) – Microsoft Support

    KB article for Exchange 2019 CU14.

    https://support.microsoft.com/help/5129957
  6. Description of version 2 of the security update for Microsoft Exchange Server 2016 CU23 October 2, 2026 (KB5129958) – Microsoft Support

    KB article for Exchange 2016 CU23.

    https://support.microsoft.com/help/5129958
  7. Exchange Server build numbers and release dates – Microsoft Learn

    Build numbers of the September SUs and v2 from October 2, 2026.

    https://learn.microsoft.com/en-us/exchange/new-features/build-numbers-and-release-dates
  8. Published calendar (.ics) returns HTTP 500 for calendar applications – Microsoft Support
  9. ContentEngine deadlock because of missing Korean WordBreaker rule files – Microsoft Support
  10. Availability (free/busy) fails for delegated mailboxes in Exchange hybrid deployments using Graph API only – Microsoft Support

    Symptoms, SettingOverride workaround, and investigation status.

    https://support.microsoft.com/en-us/servicing/exchange/server/update/2026/5127092
  11. V2 Security Updates Exchange 2016-SE (Sep2026) – EighTwOne

    Overview of v2 builds and KBs, with a note about CU-specific packages.

    https://eightwone.com/2026/10/03/v2-security-updates-exchange-2016-se-sep2026/

Comments

Comments are loaded from GitHub / Giscus.