Microsoft has pushed out an out-of-band security update for Exchange Server to address CVE-2026-96940, a high-severity vulnerability that could allow an authenticated attacker to read emails and attachments belonging to other users in the same organization. The flaw does not allow access across tenant boundaries.
The vulnerability was discovered internally, and Microsoft says it is not aware of active exploitation. However, the company believes the flaw could be consistently exploited and notes that similar vulnerabilities have been exploited in the past, so it advises administrators to update sooner rather than later.
The rollout has been somewhat muddled. A related service-side fix for Exchange Online was deployed late last week without an accompanying KB article, which Microsoft later acknowledged was because the update was published ahead of its intended schedule. The on-premises update applies to Exchange Server Subscription RTM, Exchange Server 2019 cumulative updates 14 and 15, and Exchange Server 2016 cumulative update 23.
Microsoft recommends that customers review the deployment guidance and apply the September 2026 v2 update at the earliest opportunity. It also advises installing the update on all Exchange Servers and on servers and workstations running the Exchange Management Tools to ensure compatibility between management tools clients and servers.