Microsoft Urges Immediate Updates to Fix High-Severity Exchange Server Flaw
Microsoft has released a critical security update for its on-premises Exchange Server to patch a high-severity privilege escalation flaw, identified as CVE-2026-96940. The vulnerability could allow authenticated users to access other mailboxes within the same organization, potentially exposing sensitive business communications and attachments. Microsoft rated the flaw with a CVSS score of 8.8, indicating a high likelihood of exploitation, although no active attacks have been reported yet.
The issue stems from weak authorization controls in Exchange Server, which could let attackers read email messages and attachments without further user interaction. Organizations running vulnerable Exchange Server deployments, including those on Exchange Server Subscription Edition, Exchange 2016, and Exchange 2019, must install the V2 September 2026 updates. Earlier September patches did not include the necessary fix.
Exchange Online customers are already protected and do not need to take action. However, hybrid environments must update all on-premises Exchange servers, including management systems. Some organizations may face additional challenges, such as needing to enroll in Microsoft’s Period 2 Extended Security Update (ESU) program for older Exchange versions, which requires separate licensing. Known issues with the update include problems with published calendar links and Korean-language mailbox scenarios, which Microsoft plans to address in future updates.