On 2 October 2026 Microsoft shipped an unscheduled second version (V2) of the September update for on-premises Microsoft Exchange Server to fix CVE-2026-96940 — a high-severity improper authorization issue (CVSS 8.8) that can let an already authenticated attacker read other users’ mailboxes and attachments within the same organisation, without crossing tenant boundaries. Microsoft found the flaw internally and says it is not aware of active exploitation, but rates exploitation as more likely and notes similar issues have been exploited before.
The release sequence was messy: Exchange Online received a service-side fix late the prior week before KB articles were ready, leaving administrators applying updates without full explanation. Microsoft acknowledged the V2 package published ahead of its planned schedule. For hybrid and on-prem the consequence is clear: if you installed the September SU without V2, you are not protected against mailbox read access.
V2 applies to Exchange Server Subscription Edition RTM, Exchange 2019 CU14/CU15, and Exchange 2016 CU23 (2016/2019 via Period 2 Extended Security Updates). Microsoft recommends installing on all Exchange servers and Exchange Management Tools hosts, then rebooting and verifying services. V2 also addresses additional CVEs from internal and partner reporting; Messageware and Help Net Security emphasise hybrid estates must patch every on-prem node, including servers kept only for recipient management.
For Nordic agencies and enterprises with remaining on-prem Exchange — often tied to archiving, records, or specific compliance needs — the risk is stolen or guessed credentials plus CVE-2026-96940 enabling reads of executive or HR mailboxes without further user interaction. It is not anonymous internet RCE, but it is serious for privacy and insider investigations.
What IT and security leads should do now
Confirm September SU V2 (KB5129955–KB5129958 depending on build) is installed on every Exchange role. Run Health Checker after update, reboot, and verify services. Review audit/logs for unusual mailbox access from service accounts and standard users. Strengthen credential hygiene and phishing-resistant MFA for accounts with mailbox access. In hybrid: patch even “minimal” on-prem servers; the cloud does not protect local mailboxes.
Evidence status
Microsoft Support KB5129955 family, MSRC CVE-2026-96940, Help Net Security and Messageware (October 2026).
In investigations where email is evidence, mailbox read via weak authorization raises integrity questions even without outward exfiltration: who knew what, when, and through which account? Enable and preserve Exchange auditing per policy, and correlate with identity logs (Entra ID / AD) if the same credentials appear from unusual locations. For organisations deferring ESU costs on 2016/2019: October V2 shows “minimal on-prem” does not remove patch duty — only extends it via paid programs.
Internal comms should explain why V2 arrived “late” yet urgent: users may notice nothing, but security teams must treat it like a KEV-class issue because the impact is reading others’ mail, not merely service disruption. Schedule patch windows so Management Tools and transport nodes update together to avoid version skew that itself causes outages.
For legal and privacy teams: assess whether mailbox read could trigger GDPR personal data breach notification, especially if service accounts with broad access were abused. Document which mailboxes may be affected and whether automated log analysis can show unusual access patterns in audit. In hybrid estates, remember Graph-only free/busy issues V2 also fixes may signal September packages already affected operations; plan reboot and validation in the same window as the security fix.