Microsoft reissues September Exchange security updates to cover CVE-2026-96940
Microsoft shipped V2 builds of its September 2026 Exchange Server security updates at the start of October, adding a fix for an elevation of privilege flaw it found internally.
At a glance
- The only difference between the original September 2026 release and the V2 updates is a fix for CVE-2026-96940, an elevation of privilege flaw.
- Microsoft says it found the vulnerability internally and is not aware of active exploitation, but rates exploitation as likely.
- V2 updates cover Exchange Server Subscription Edition RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23; the 2016 and 2019 builds require Period 2 Extended Security Update enrolment.
- Two known issues remain unfixed: published calendar (.ics) links returning HTTP 500, and ContentEngine deadlocks affecting Korean-language mail.
Microsoft has reissued its September 2026 security updates for on-premises Exchange Server as V2 builds, adding a patch for a vulnerability it discovered after the original release. Daily CyberSecurity reports that the sole difference between the two releases is the addition of CVE-2026-96940, and that Microsoft "identified the vulnerability internally" and is "not aware of active exploitation." Administrators who already installed September's updates are not finished: the V2 package has to go on top, because the original build does not contain the new fix.
What happened
Franky's Web reports that the update, KB5129955 — "Security Update for Exchange Server SE RTM SU10v2" — appeared on October 1, and unusually arrived through Windows Update rather than as the standalone installer Exchange admins are used to, which caused some initial confusion about what it was. Daily CyberSecurity dates Microsoft's V2 announcement to October 3. Franky's Web notes the Exchange team pushed the release out ahead of its intended schedule and is urging administrators to install it quickly.
Technical details
Neither source publishes full technical detail on CVE-2026-96940. Franky's Web describes it as an elevation of privilege issue and notes that, while no exploitation is known, "exploitation is considered likely" — Microsoft's own exploitability assessment. Daily CyberSecurity says no CVSS score, attack vector or impact description accompanied the write-up and points readers to Microsoft's Security Update Guide for the full entry. Security updates for Exchange are cumulative, so only the newest one needs to be installed rather than the whole chain.
Who is affected
The V2 updates cover three product lines, according to Daily CyberSecurity: Exchange Server Subscription Edition RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23. Exchange Server 2016 and 2019 are out of mainstream support, so only organisations enrolled in the Period 2 Extended Security Update programme are eligible to receive those builds — leaving unenrolled estates with no fix and a flaw Microsoft itself rates as likely to be exploited. Both sources also stress that the update belongs on every Exchange server, including machines used only for management, and that workstations with the Exchange Management Tools installed should be patched as well.
What to do
Run the Exchange Server Health Checker script first to find servers that have fallen behind, apply the current cumulative update if one is required, then install the latest security update, reboot and confirm that all Exchange services came back up. Franky's Web gives Get-Command Exsetup.exe | ForEach-Object {$_.FileVersionInfo} as the way to verify the resulting build number.
Two known issues carry over into V2 and are not fixed yet, per both sources: published calendar (.ics) links return HTTP 500 to calendar applications, and a ContentEngine deadlock caused by missing Korean word-breaker rule files affects mailboxes with Korean-language mail. Microsoft says both will be addressed in a future update. Neither is a reason to delay the security fix, but service desks should expect the calendar complaints.
Related CVEs
Sources
- Microsoft Reissues September 2026 Exchange Server Security Updates to Add CVE-2026-96940 — Daily CyberSecurity (securityonline.info)
- New security updates for Exchange Server (September 2026) V2 — Franky's Web
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



