Microsoft has shipped a V2 release of its September 2026 Exchange Server security updates. The only change from the original release is one added vulnerability, CVE-2026-96940. The Exchange Team says it published this update “ahead of its intended schedule,” and it urges admins to install it quickly.
Route critical Microsoft CVEs to one Slack channel, everything else to another.
Try Team free for 14 daysWhat Changed in the V2 Release
The Exchange Team explains it directly. “The difference between the original September 2026 Security Update release and this V2 release is an addition of CVE-2026-96940,” the blog states.
Microsoft found the flaw itself. According to the team, “We identified the vulnerability internally and are not aware of active exploitation.” The blog does not describe the bug’s type or severity. Instead, it points readers to the Security Update Guide for CVE details.
Which Versions Get the Patch
The new Exchange Server security updates cover three product lines:
- Exchange Server Subscription Edition (SE) RTM
- Exchange Server 2019 CU14 and CU15
- Exchange Server 2016 CU23
However, there is a catch for older versions. Exchange 2016 and 2019 are out of support. Only organizations enrolled in the Period 2 Extended Security Update (ESU) program can download these fixes. That program covers updates released between May and October 2026. Everyone else should move to Exchange SE, Microsoft says.
Exchange Online and Hybrid Customers
Exchange Online is already protected. Even so, hybrid customers still have work to do. The blog notes that the update “needs to be installed on your Exchange servers, even if they are used only for management purposes.” Microsoft also recommends patching every workstation that runs the Exchange Management Tools.
Known Issues and Fixes
This release carries two known issues. First, published calendar (.ics) links return an HTTP 500 error. Second, a ContentEngine deadlock affects mailboxes with Korean-language email. Microsoft plans to fix both in a future update.
On the plus side, the update resolves two hybrid problems. Wrapper messages no longer appear in shared mailbox inboxes. In addition, free/busy lookups now work for delegated mailboxes in Graph-only hybrid setups.
How to Install
Security updates are cumulative, so admins only need the latest one. Microsoft suggests running the Exchange Server Health Checker script first to find servers that lag behind. After setup, reboot and confirm that all Exchange services have started. Disabled services signal an interrupted install.
Full guidance appears in the Exchange Team’s post on the September 2026 V2 Exchange Server security updates. Given the early release, admins should not wait for the next patch cycle.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!