Microsoft has released updated security patches for Exchange Server as part of the September 2026 V2 updates, addressing a critical vulnerability identified as CVE-2026-96940. This flaw allows authenticated attackers to access mailboxes within the same organization, posing a significant risk of data exposure for businesses using on-premises Exchange Servers. The vulnerability is rated with a CVSS score of 8.8, highlighting its severity. Unlike some attacks that require user interaction, this flaw can be exploited without any action from the user once the attacker is authenticated. The vulnerability does not cross tenant boundaries, limiting its impact to users within the same organization.

Microsoft discovered the flaw internally and has no evidence of active exploitation at this time. The update for CVE-2026-96940 was released ahead of schedule, and some documentation might have been incomplete upon announcement. The updated packages are crucial for those using Exchange Server Subscription Edition RTM, as well as versions 2019 CU14 and CU15, and 2016 CU23. Administrators should ensure they download the correct package corresponding to their installed version and cumulative update.

Organizations that have previously installed the September security updates need to apply the new V2 updates to address this vulnerability. While Exchange Online users are protected, businesses with hybrid deployments must update their local servers, including management-only servers, to remain secure. Microsoft has provided tools like the Exchange Server Health Checker script and the Exchange Update Wizard to assist administrators in identifying and applying necessary updates.

Administrators are advised to install the updates promptly, restart the servers, and verify the correct functioning of all Exchange services. Known issues with the update include errors with published calendar files and Korean language emails, which Microsoft plans to address in future patches. Microsoft emphasizes the importance of applying these updates immediately to mitigate the mailbox access vulnerability and ensure continued security of mail services.