Microsoft Reissues September 2026 Exchange Server Updates (V2) for CVE-2026-96940 Mailbox Authorization Flaw

Microsoft Reissues September 2026 Exchange Server Updates (TL-2026-2864), also tracked as Exchange September 2026 V2 Security Updates, is a high-severity software vulnerability scored CVSS 8.8, first published 2026-10-03. It has no confirmed attribution, affects Microsoft Exchange Server Subscription Edition, references 1 CVE (CVE-2026-96940), maps to 4 MITRE ATT&CK techniques (T1078, T1087.003, T1114), and is covered by 9 detection rules and 8 indicators of compromise.

Key facts for TL-2026-2864

Threat ID
TL-2026-2864
Also known as
Exchange September 2026 V2 Security Updates, Exchange SE SU10v2
Severity
HIGH
CVSS
8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
2026-10-03
Last reviewed
2026-10-03
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, health, enterprise, technology
Target regions
Global
Detection rules
9
Indicators of compromise
8

Malware and tooling in Microsoft Reissues September 2026 Exchange Server Updates

Malware and tooling: Exchange Server Health Checker (HealthChecker.ps1)

Microsoft released V2 of its September 2026 Exchange Server security updates after the original release (SU10, 8 September) did not include a fix for CVE-2026-96940, a weak authorization flaw (CVSS 8.8) that lets an authenticated attacker access other users' mailboxes within the same organization. Microsoft found the flaw internally and reported no active exploitation.

How Microsoft Reissues September 2026 Exchange Server Updates works

CVE-2026-96940 is a weak-authorization vulnerability (CWE-1390) in on-premises Microsoft Exchange Server. The CVE record describes it as allowing an authenticated attacker to elevate privileges over a network; Microsoft's Exchange Team and press coverage describe the practical impact as an authenticated attacker accessing other users' mailboxes in the same organization, exposing email messages and attachments. The scoring is CVSS 3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (8.8, High). No user interaction is required, and access does not cross tenant boundaries. Exchange Online customers are already protected.

Affected products are Exchange Server Subscription Edition (SE) RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23. Per CVE tracker data, vulnerable build ranges are 15.1.x below 15.1.2507.75 (2016 CU23), 15.2.x below 15.2.1544.48 (2019 CU14), 15.2.x below 15.2.1748.53 (2019 CU15) and 15.2.x below 15.2.2562.53 (SE RTM).

The original September 2026 Exchange security updates were released on 8 September 2026 (SE SU10 KB5121608; 2019 CU15 KB5121609; 2019 CU14 KB5121610; 2016 CU23 KB5121611) and addressed nine other CVEs, but not CVE-2026-96940. The CVE was reserved on 23 September 2026. The SE SU10v2 package (KB5129955) began appearing through Windows Update/WSUS on 1 October 2026 before any documentation existed, and Microsoft announced the 'September 2026 V2 Exchange Server Security Updates' on the Exchange Team Blog on 2 October 2026. The only difference between the original release and V2 is the addition of CVE-2026-96940. Microsoft said it published the V2 updates ahead of its intended schedule so attackers would not discover and exploit the flaw first.

Microsoft found the vulnerability internally and was not aware of active exploitation. The CVE is not in the CISA KEV catalog (version 2026.10.02), and no public proof-of-concept was detected by CVE trackers. Administrators who installed the earlier September release should install the V2 packages rather than assume they are protected. Updates are applied to every Exchange server and Exchange Management Tools workstation, including management-only systems in hybrid deployments. Exchange 2016 and 2019 updates are available only to organizations enrolled in the Extended Security Update (ESU) Period 2 program (May-October 2026), with no further extensions planned. Cyber Security News notes a separate earlier Exchange flaw, CVE-2026-62911 (authentication relay), as related context.

MITRE ATT&CK techniques used in TL-2026-2864

Initial Access

T1078 Valid Accounts

Discovery

T1087.003 Account Discovery: Email Account

Collection

T1114 Email Collection; T1114.002 Email Collection: Remote Email Collection

Affected products and versions in Microsoft Reissues September 2026 Exchange Server Updates

  • Microsoft — Exchange Server Subscription Edition
    Vulnerable versions: RTM (builds below 15.2.2562.53, including SU10 15.2.2562.49)
    Fixed in: SU10v2 (KB5129955)
  • Microsoft — Exchange Server 2019
    Vulnerable versions: CU15 (below 15.2.1748.53); CU14 (below 15.2.1544.48)
    Fixed in: September 2026 V2 security update (ESU Period 2)
  • Microsoft — Exchange Server 2016
    Vulnerable versions: CU23 (below 15.1.2507.75)
    Fixed in: September 2026 V2 security update (ESU Period 2)

Remediation for Microsoft Reissues September 2026 Exchange Server Updates

Patches

  • Exchange SE RTM: KB5129955 (SU10v2)
  • Exchange 2019 CU15, 2019 CU14, 2016 CU23: V2 security updates (ESU Period 2 enrollees), superseding KB5121609, KB5121610, KB5121611

Immediate actions

  • Install the September 2026 V2 Exchange security update on every on-premises Exchange server, even if the original September update (SU10, 8 Sep 2026) is already installed
  • Also update Exchange Management Tools workstations and management-only servers in hybrid deployments
  • Restart servers after installation and confirm Exchange services function properly

Workarounds

  • None documented in sources; Exchange Online customers are already protected

Longer-term hardening

  • Run the Exchange Server Health Checker script to identify missing updates
  • Identify installed version and cumulative update level (Get-Command Exsetup.exe) before and after patching
  • Plan migration off Exchange 2016/2019 or to Exchange SE; their updates are available only through ESU Period 2 (May-October 2026) with no further extensions planned

CVEs associated with Microsoft Reissues September 2026 Exchange Server Updates

CVE-2026-96940

Weaknesses (CWE) in Microsoft Reissues September 2026 Exchange Server Updates

CWE-1390

Timeline of Microsoft Reissues September 2026 Exchange Server Updates

  • Microsoft releases the original September 2026 Exchange security updates (SE SU10 KB5121608; 2019 CU15 KB5121609; 2019 CU14 KB5121610; 2016 CU23 KB5121611), which do not include a fix for CVE-2026-96940.
  • CVE-2026-96940 is reserved; Microsoft's own teams had identified the weak-authorization flaw internally.
  • KB5129955 (Exchange SE RTM SU10v2) begins appearing via Windows Update/WSUS before any documentation is published; administrators initially advise caution.
  • CVE-2026-96940 is published with CVSS 3.1 base score 8.8 and CWE-1390; MSRC advisory links the Security Update Guide entry.
  • Exchange Team Blog publishes 'Released: September 2026 V2 Exchange Server Security Updates'; the only change from the original release is the addition of CVE-2026-96940.
  • Cyber Security News, Cryptika and Neowin report the V2 reissue; CVE record updated; flaw not in CISA KEV and no known exploitation.

Sources cited for Microsoft Reissues September 2026 Exchange Server Updates

More in vulnerability

Detection coverage for TL-2026-2864

As of 2026-10-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2864 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats