Microsoft Reissues September 2026 Exchange Server Updates (V2) for CVE-2026-96940 Mailbox Authorization Flaw
Microsoft Reissues September 2026 Exchange Server Updates (TL-2026-2864), also tracked as Exchange September 2026 V2 Security Updates, is a high-severity software vulnerability scored CVSS 8.8, first published 2026-10-03. It has no confirmed attribution, affects Microsoft Exchange Server Subscription Edition, references 1 CVE (CVE-2026-96940), maps to 4 MITRE ATT&CK techniques (T1078, T1087.003, T1114), and is covered by 9 detection rules and 8 indicators of compromise.
Key facts for TL-2026-2864
- Threat ID
- TL-2026-2864
- Also known as
- Exchange September 2026 V2 Security Updates, Exchange SE SU10v2
- Severity
- HIGH
- CVSS
- 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-10-03
- Last reviewed
- 2026-10-03
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, enterprise, technology
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 8
Malware and tooling in Microsoft Reissues September 2026 Exchange Server Updates
Malware and tooling: Exchange Server Health Checker (HealthChecker.ps1)
Microsoft released V2 of its September 2026 Exchange Server security updates after the original release (SU10, 8 September) did not include a fix for CVE-2026-96940, a weak authorization flaw (CVSS 8.8) that lets an authenticated attacker access other users' mailboxes within the same organization. Microsoft found the flaw internally and reported no active exploitation.
How Microsoft Reissues September 2026 Exchange Server Updates works
CVE-2026-96940 is a weak-authorization vulnerability (CWE-1390) in on-premises Microsoft Exchange Server. The CVE record describes it as allowing an authenticated attacker to elevate privileges over a network; Microsoft's Exchange Team and press coverage describe the practical impact as an authenticated attacker accessing other users' mailboxes in the same organization, exposing email messages and attachments. The scoring is CVSS 3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (8.8, High). No user interaction is required, and access does not cross tenant boundaries. Exchange Online customers are already protected.
Affected products are Exchange Server Subscription Edition (SE) RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23. Per CVE tracker data, vulnerable build ranges are 15.1.x below 15.1.2507.75 (2016 CU23), 15.2.x below 15.2.1544.48 (2019 CU14), 15.2.x below 15.2.1748.53 (2019 CU15) and 15.2.x below 15.2.2562.53 (SE RTM).
The original September 2026 Exchange security updates were released on 8 September 2026 (SE SU10 KB5121608; 2019 CU15 KB5121609; 2019 CU14 KB5121610; 2016 CU23 KB5121611) and addressed nine other CVEs, but not CVE-2026-96940. The CVE was reserved on 23 September 2026. The SE SU10v2 package (KB5129955) began appearing through Windows Update/WSUS on 1 October 2026 before any documentation existed, and Microsoft announced the 'September 2026 V2 Exchange Server Security Updates' on the Exchange Team Blog on 2 October 2026. The only difference between the original release and V2 is the addition of CVE-2026-96940. Microsoft said it published the V2 updates ahead of its intended schedule so attackers would not discover and exploit the flaw first.
Microsoft found the vulnerability internally and was not aware of active exploitation. The CVE is not in the CISA KEV catalog (version 2026.10.02), and no public proof-of-concept was detected by CVE trackers. Administrators who installed the earlier September release should install the V2 packages rather than assume they are protected. Updates are applied to every Exchange server and Exchange Management Tools workstation, including management-only systems in hybrid deployments. Exchange 2016 and 2019 updates are available only to organizations enrolled in the Extended Security Update (ESU) Period 2 program (May-October 2026), with no further extensions planned. Cyber Security News notes a separate earlier Exchange flaw, CVE-2026-62911 (authentication relay), as related context.
MITRE ATT&CK techniques used in TL-2026-2864
Initial Access
Discovery
T1087.003 Account Discovery: Email Account
Collection
T1114 Email Collection; T1114.002 Email Collection: Remote Email Collection
Affected products and versions in Microsoft Reissues September 2026 Exchange Server Updates
- Microsoft — Exchange Server Subscription Edition
Vulnerable versions: RTM (builds below 15.2.2562.53, including SU10 15.2.2562.49)
Fixed in: SU10v2 (KB5129955) - Microsoft — Exchange Server 2019
Vulnerable versions: CU15 (below 15.2.1748.53); CU14 (below 15.2.1544.48)
Fixed in: September 2026 V2 security update (ESU Period 2) - Microsoft — Exchange Server 2016
Vulnerable versions: CU23 (below 15.1.2507.75)
Fixed in: September 2026 V2 security update (ESU Period 2)
Remediation for Microsoft Reissues September 2026 Exchange Server Updates
Patches
- Exchange SE RTM: KB5129955 (SU10v2)
- Exchange 2019 CU15, 2019 CU14, 2016 CU23: V2 security updates (ESU Period 2 enrollees), superseding KB5121609, KB5121610, KB5121611
Immediate actions
- Install the September 2026 V2 Exchange security update on every on-premises Exchange server, even if the original September update (SU10, 8 Sep 2026) is already installed
- Also update Exchange Management Tools workstations and management-only servers in hybrid deployments
- Restart servers after installation and confirm Exchange services function properly
Workarounds
- None documented in sources; Exchange Online customers are already protected
Longer-term hardening
- Run the Exchange Server Health Checker script to identify missing updates
- Identify installed version and cumulative update level (Get-Command Exsetup.exe) before and after patching
- Plan migration off Exchange 2016/2019 or to Exchange SE; their updates are available only through ESU Period 2 (May-October 2026) with no further extensions planned
CVEs associated with Microsoft Reissues September 2026 Exchange Server Updates
CVE-2026-96940
Weaknesses (CWE) in Microsoft Reissues September 2026 Exchange Server Updates
CWE-1390
Timeline of Microsoft Reissues September 2026 Exchange Server Updates
- Microsoft releases the original September 2026 Exchange security updates (SE SU10 KB5121608; 2019 CU15 KB5121609; 2019 CU14 KB5121610; 2016 CU23 KB5121611), which do not include a fix for CVE-2026-96940.
- CVE-2026-96940 is reserved; Microsoft's own teams had identified the weak-authorization flaw internally.
- KB5129955 (Exchange SE RTM SU10v2) begins appearing via Windows Update/WSUS before any documentation is published; administrators initially advise caution.
- CVE-2026-96940 is published with CVSS 3.1 base score 8.8 and CWE-1390; MSRC advisory links the Security Update Guide entry.
- Exchange Team Blog publishes 'Released: September 2026 V2 Exchange Server Security Updates'; the only change from the original release is the addition of CVE-2026-96940.
- Cyber Security News, Cryptika and Neowin report the V2 reissue; CVE record updated; flaw not in CISA KEV and no known exploitation.
Sources cited for Microsoft Reissues September 2026 Exchange Server Updates
- Microsoft Pushes New Exchange V2 Update After Discovering New Security Flaw
- Released: September 2026 V2 Exchange Server Security Updates
- MSRC Security Update Guide: CVE-2026-96940
- Security Updates Exchange 2016-SE (Sep2026)
- Exchange Server SE SU10 has been released
- Exchange SE Update KB5129955 is circulating via Windows Update / WSUS
- CVE-2026-96940: CWE-1390 Weak Authentication in Microsoft Exchange Server (OffSeq Threat Radar)
- CVE-2026-96940: Vulnerability Details - Analysis & Fix (The Hacker Wire)
- Microsoft Pushes New Exchange V2 Update After Discovering New Security Flaw (Cryptika)
- On-premises Exchange administrators must install V2 security updates to fix elevation flaws (Neowin)
More in vulnerability
- Rejetto HTTP File Server (HFS) 3.x session forgery via predictable Math.random() signing key leads to unauthenticated admin access and RCE (CVE-2026-61500) under active exploitation
- Fortra Patches Critical Vulnerabilities in BoKS Privileged Access Manager (CVE-2026-79901, CVE-2026-79898, CVE-2026-12627)
- Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes (CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, CVE-2026-67273)
- GitLab AI Gateway critical RCE via prompt template sandbox escape (CVE-2026-90970)
- CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490 (local privilege escalation to root), chained in an agentic-AI attack on DIVD
Detection coverage for TL-2026-2864
As of 2026-10-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2864 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.