The date and name invite a patch-tracking mistake

Microsoft released its “September 2026 V2” Exchange Server security updates on 2 October. The Exchange Team says the difference from the original September release is the addition of a fix for CVE-2026-96940. A server that received the earlier September package has not necessarily received this correction.

Microsoft describes the vulnerability as weak authorization in Exchange Server. An authenticated attacker could exceed the mailbox permissions they should hold. Reports have highlighted the potential to read other users' messages and attachments within the same organization. That is an exposure to address, not evidence that data theft has occurred.

Do not confuse likelihood with confirmed attacks

Microsoft's exploitability assessment is a forecast, not a statement that it observed active exploitation. Use the current Microsoft CVE page for the exact affected builds and any later change in status.

Cloud mailboxes do not erase the local-server inventory

The V2 updates cover Exchange Server Subscription Edition and specified Exchange 2019 and 2016 cumulative-update branches. Older servers require the applicable Extended Security Update enrollment to receive these releases. Microsoft says Exchange Online is protected, but organizations using cloud mailboxes should still identify any local Exchange servers or management components they retain.

The server's edition and cumulative-update branch determine which package and resulting build to expect. Comparing build numbers across different branches can give a false answer. Administrators should verify the actual running version after installation rather than rely only on a deployment system's success indicator.

Make V2 visible in the patch record

  1. 1

    List every remaining server. Include Subscription Edition, Exchange 2019 and 2016, and local servers retained for management alongside Exchange Online.

  2. 2

    Map to the correct package. Record the cumulative-update branch and ESU eligibility where required. Select the matching V2 security update from Microsoft's release guidance.

  3. 3

    Install and verify. Follow the supported installation sequence, confirm the resulting build, and run the recommended Exchange health checks.

  4. 4

    Keep investigation separate. If account or mailbox activity is suspicious, review it against its own evidence. A patch closes the flaw but cannot prove it was never used.

The original September checkbox is not enough

Add a distinct “September V2 / CVE-2026-96940” field to Exchange patch tracking. Record the package, the post-install build and who verified it. An authenticated entry condition does not make the issue harmless: an already compromised ordinary account could benefit from an authorization failure.

This topic came through a Cyber Security Hub newsletter. Threat Field Notes checked Microsoft's release and update guidance before writing this note.