securityonline.info 3 Oct 2026, 01:00 UTC

Microsoft Reissues Exchange Updates With New CVE-2026-96940 Flaw

Microsoft Reissues Exchange Updates With New CVE-2026-96940 Flaw
CyberSIXT Evidence Panel
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

MICROSOFT has reissued the September 2026 security updates for Exchange Server as a V2 release, adding one new vulnerability: CVE-2026-96940. The Exchange Team says the update was published ahead of schedule and urges admins to apply it promptly.

Microsoft internal assessment indicates the flaw was found by the team and there is no known active exploitation at this time, though the specific bug type or severity is not described in the announcement and readers are directed to the Security Update Guide for CVE details.

The patched product lines in the V2 release cover Exchange Server Subscription Edition (SE) RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23. Older versions are subject to the Extended Security Update (ESU) programme, which only covers updates released between May and October 2026, while others are advised to migrate to Exchange SE.

Exchange Online is protected, but hybrid customers should still install the update on on-premises Exchange servers used for management, and patch all workstations running the Exchange Management Tools. Known issues include HTTP 500 errors on published calendar (.ics) links and a ContentEngine deadlock affecting Korean-language mailboxes; Microsoft plans fixes in a future update.

The release also resolves two hybrid issues: wrapper messages disappearing from shared mailbox inboxes and functional free/busy lookups for delegated mailboxes in Graph-only hybrid setups. Administrators should run the Exchange Server Health Checker, reboot after installation, and verify that all services start. The guidance notes installing only the latest cumulative update.

View full article

Article by CyberSIXT