Microsoft released a new version of its September 2026 Exchange Server security updates. The only change is a fix for CVE-2026-96940. Help Net Security reported on 5 October that the flaw is rated high severity. It said a user with a valid login might read other people's emails and attachments inside the same organisation. It does not reach across tenants, which are separate customer accounts. The update covers Exchange Server Subscription Edition, 2019 CU14 and CU15, and 2016 CU23.
Microsoft said its own staff found the flaw and that it knows of no active attacks. Help Net Security said Microsoft believes the flaw could be exploited reliably, and that this type of bug has been abused before. Microsoft said the update went out ahead of its planned date. It did not say why. Microsoft's post sends readers to a separate article for details, and says documentation may not be complete yet.
Anyone running their own Exchange servers needs to install the update. Microsoft says this includes machines used only for management tools. Exchange Online customers are already protected. Exchange 2016 and 2019 are out of support, so only customers in Microsoft's paid Period 2 extended program can get this fix for them.