What changed
The date and name invite a patch-tracking mistake
Microsoft released its “September 2026 V2” Exchange Server security updates on 2 October. The Exchange Team says the difference from the original September release is the addition of a fix for CVE-2026-96940. A server that received the earlier September package has not necessarily received this correction.
Microsoft describes the vulnerability as weak authorization in Exchange Server. An authenticated attacker could exceed the mailbox permissions they should hold. Reports have highlighted the potential to read other users' messages and attachments within the same organization. That is an exposure to address, not evidence that data theft has occurred.
Do not confuse likelihood with confirmed attacks
Affected estate
Cloud mailboxes do not erase the local-server inventory
The V2 updates cover Exchange Server Subscription Edition and specified Exchange 2019 and 2016 cumulative-update branches. Older servers require the applicable Extended Security Update enrollment to receive these releases. Microsoft says Exchange Online is protected, but organizations using cloud mailboxes should still identify any local Exchange servers or management components they retain.
The server's edition and cumulative-update branch determine which package and resulting build to expect. Comparing build numbers across different branches can give a false answer. Administrators should verify the actual running version after installation rather than rely only on a deployment system's success indicator.
Defender workflow
Make V2 visible in the patch record
- 1
List every remaining server. Include Subscription Edition, Exchange 2019 and 2016, and local servers retained for management alongside Exchange Online.
- 2
Map to the correct package. Record the cumulative-update branch and ESU eligibility where required. Select the matching V2 security update from Microsoft's release guidance.
- 3
Install and verify. Follow the supported installation sequence, confirm the resulting build, and run the recommended Exchange health checks.
- 4
Keep investigation separate. If account or mailbox activity is suspicious, review it against its own evidence. A patch closes the flaw but cannot prove it was never used.
Defender note
The original September checkbox is not enough
Add a distinct “September V2 / CVE-2026-96940” field to Exchange patch tracking. Record the package, the post-install build and who verified it. An authenticated entry condition does not make the issue harmless: an already compromised ordinary account could benefit from an authorization failure.
This topic came through a Cyber Security Hub newsletter. Threat Field Notes checked Microsoft's release and update guidance before writing this note.