Microsoft Warns Exchange Admins to Patch Critical Flaw Immediately


exchange server update
Image credit: Microsoft

Microsoft patched CVE-2026-96940, a critical elevation-of-privilege vulnerability affecting multiple on-premises Exchange Server versions.

The flaw stems from weak authorization controls. An authenticated attacker could exploit it over a network to access other users’ mailboxes within the same organization.

Microsoft discovered the vulnerability internally. Exchange Online customers do not need to take action because Microsoft has already applied protections to the cloud service.

Microsoft releases a second round of September updates

Microsoft issued a second version of its September 2026 Exchange Server security updates specifically to address CVE-2026-96940.

Admins need to install the update that matches their Exchange Server version. Exchange Server SE RTM requires KB5129955, Exchange Server 2016 CU23 requires KB5129958, Exchange Server 2019 CU15 requires KB5129956, and Exchange Server 2019 CU14 requires KB5129957.

Microsoft recommends installing the applicable update immediately, particularly on internet-facing Exchange servers.

Admins can also run the Exchange Server Health Checker to identify missing security updates and unsupported configurations.

Exchange 2016 and 2019 customers face restrictions

Microsoft only provides the new Exchange Server 2016 and Exchange Server 2019 patches to organizations enrolled in the Period 2 Extended Security Update program.

Organizations running those versions without ESU coverage will not receive the fix through normal support channels.

Microsoft recommends migrating unsupported deployments to Exchange Server Subscription Edition to continue receiving security updates.

Some known issues remain after installation

The security updates also come with several known issues administrators should watch for.

Published calendar .ics files may return HTTP 500 errors after installing the update. Microsoft has also documented ContentEngine deadlocks affecting some Korean-language email processing scenarios.

After installing the appropriate security update, admins should restart the Exchange server and verify that Exchange services start normally.

Microsoft recommends using SetupAssist if the update fails or administrators encounter problems during installation.

Organizations should also confirm that the expected Exchange build and security update appear after the installation completes.

The Exchange Server patch arrives as Microsoft makes other changes across its messaging infrastructure. The company is also tightening Exchange Online EWS access beginning October 10.

The update also follows recent attacks in which Warlock ransomware exploited SharePoint flaws to compromise enterprise networks.

More about the topics: exchange, microsoft

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages