Microsoft patches critical Exchange Server vulnerability in urgent update
Microsoft has issued an emergency security update for Exchange Server to address a critical vulnerability (CVE-2026-96940) that could allow authenticated attackers to access emails and attachments of other users within the same organization. The flaw does not permit cross-tenant access, but Microsoft has warned that it could be consistently exploited, citing past incidents of similar vulnerabilities being abused.
The Exchange Server Team confirmed that the bug was discovered internally and that they are not aware of any active exploitation. Despite this, the company is urging administrators to apply the update as soon as possible.
The rollout of the update was somewhat chaotic, with a service-side fix deployed to Exchange Online last week without accompanying documentation. Microsoft later acknowledged the misstep, explaining that the update was released ahead of its planned schedule without providing further details on why.
The security update is available for on-premises servers running Exchange Server Subscription RTM, Exchange Server 2019 cumulative updates 14 and 15, and Exchange Server 2016 cumulative update 23. Microsoft recommends reviewing the deployment guidance and installing the September 2026 v2 update promptly. They also advise updating all Exchange Servers and related management tools to ensure compatibility.