Microsoft Releases September 2026 V2 Security Updates
Microsoft has unveiled its September 2026 V2 security updates aimed at rectifying a significant vulnerability within Exchange Server.
This flaw permits authenticated attackers to access other users’ mailboxes within the same organizational structure.
Designated as CVE-2026-96940, this weakness presents a serious threat, potentially exposing sensitive email messages and attachments, thereby raising alarm for entities utilizing on-premises Exchange systems.
This vulnerability stems from inadequate authorization protocols, enabling an assailant with authenticated access to elevate their privileges across the network.
Public vulnerability databases have assigned a CVSS score of 8.8, indicating a considerable level of risk.
Notably, while some exploitations necessitate user interaction via malicious files, this particular vulnerability allows access without any user engagement. Furthermore, affected mailbox access does not traverse tenant boundaries.
Microsoft reports that its internal teams identified the vulnerability and noted no evidence of active exploitation.
Remarkably, the company confirmed that this update was released ahead of its scheduled timeline; therefore, accompanying documentation may not have been fully available at the time of the announcement.
Microsoft Reissues Exchange Server Update
The September 2026 V2 update enhances the previous September security releases by incorporating protections against CVE-2026-96940.
Organizations that implemented the earlier updates are encouraged to conduct a review of the new packages instead of assuming their servers contain this critical patch.
Updates are available for Exchange Server Subscription Edition RTM, along with Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23.
Administrators are required to select the appropriate package corresponding to their installed version and cumulative update.
This issue is distinct from CVE-2026-62911, an earlier Exchange vulnerability highlighted by Cybersecurity News, following the demonstration of an authentication relay attack.
It is crucial to note that previous research should not be misconstrued as implying the existence of an exploit for CVE-2026-96940.
Exchange Server versions 2016 and 2019 have reached their end of support. Consequently, the latest patches are exclusively accessible to organizations enrolled in Microsoft’s Period 2 Extended Security Update program, which encompasses coverage from May to October 2026.
This Period 2 program necessitates a separate purchase, applicable even for clients who previously joined the initial ESU program.
Microsoft has affirmed that no extensions will be granted post-October. Organizations lacking this coverage are advised to migrate to Exchange Server Subscription Edition to continue receiving essential security updates.
Users of Exchange Online are already safeguarded against the vulnerabilities addressed in this release.
However, businesses employing hybrid configurations must ensure their local Exchange servers are updated, including those designated solely for management purposes. Additionally, systems running Exchange Management Tools require the relevant updates.
To assist administrators, Microsoft recommends executing the Exchange Server Health Checker script to identify any missing cumulative updates, security updates, and required manual interventions.
The Exchange Update Wizard can facilitate planning the appropriate upgrade path before implementing the latest security package.
The security updates are cumulative, meaning that a server operating on a supported cumulative update does not require installation of every preceding security update in order.
After application, administrators should restart the server and verify that Exchange services are functioning correctly, followed by running the Health Checker again to determine any remaining steps.
It is worth noting that the release contains known issues, such as published calendar files returning HTTP 500 errors and ContentEngine deadlocks for emails in the Korean language.
Microsoft has indicated plans to address these issues in forthcoming updates while also rectifying problems related to shared mailbox wrapper messages and delegated mailbox availability in particular hybrid environments.

Microsoft urges its customers to assess the deployment guidance and apply the update promptly. For organizations affected, the immediate focus must be on closing the mailbox access vulnerability while ensuring that mail services remain operational and healthy following patch implementation throughout their Exchange infrastructure.
Source link: Cybersecuritynews.com.





