Microsoft Patches Critical Exchange Server Vulnerability CVE-2023-21763
Key Takeaways Microsoft has issued an urgent V2 security update for Exchange Server to address a critical vulnerability. The flaw, CVE-2026-96940, allows authenticated attackers to access other...
Key Takeaways
- Microsoft has issued an urgent V2 security update for Exchange Server to address a critical vulnerability.
- The flaw, CVE-2026-96940, allows authenticated attackers to access other users’ mailboxes within the same organization.
- Rated 8.8 CVSS, it does not require user interaction for exploitation.
- The fix is available in the September 2026 V2 security updates, and organizations that applied the initial September patch must re-apply the new version.
- Exchange Server 2016 and 2019 users require an Extended Security Update (ESU) program subscription.
Microsoft Addresses Critical Exchange Server Mailbox Access Flaw
Microsoft has released an out-of-band V2 security update for Exchange Server, patching a critical vulnerability designated CVE-2026–96940. This flaw could enable authenticated attackers to gain unauthorized access to other users’ mailboxes within the same organizational network, posing a significant risk to on-premises Exchange deployments by potentially exposing sensitive email content and attachments.
Table Of Content
The vulnerability stems from an authorization weakness, allowing an authenticated network attacker to elevate privileges. With a CVSS score of 8.8, the severity is considerable. Importantly, exploiting this flaw does not necessitate any user interaction, distinguishing it from many other attack vectors that rely on a user opening a malicious file. Microsoft has clarified that the reported mailbox access is confined to within an organization and does not extend across different tenant boundaries.
According to Microsoft, their internal teams discovered this vulnerability, and there is currently no evidence of active exploitation in the wild. The company also noted that this update was released ahead of its originally scheduled deployment, which might have resulted in some supporting documentation not being immediately available upon the announcement.
Reissued Update for Enhanced Protection
The September 2026 V2 release specifically incorporates protections against CVE-2026-96940, building upon the initial September security updates. Consequently, organizations that previously installed the earlier September release are strongly advised to review and apply these new packages to ensure comprehensive protection, rather than assuming their systems are already secure against this particular vulnerability.
Updates are available for Exchange Server Subscription Edition RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23. Administrators must carefully select the specific update package that corresponds to their installed Exchange Server version and cumulative update level.
This new vulnerability, CVE-2026-96940, is distinct from CVE-2026-62911, an earlier Exchange vulnerability that garnered attention after a public proof of concept demonstrated an authentication relay attack. It is crucial not to conflate the two; the existence of an exploit for CVE-2026-62911 does not imply an exploit for CVE-2026-96940.
Extended Security Update Program and Hybrid Deployments
For Exchange Server 2016 and 2019, which are now out of mainstream support, the latest patches are exclusively available to organizations participating in Microsoft’s Period 2 Extended Security Update program. This program covers security updates from May through October 2026.
Enrollment in Period 2 requires a separate purchase, even for customers who participated in the earlier ESU program. Microsoft has stated that no further extensions will be offered beyond October. Organizations without current ESU coverage should prioritize migrating to Exchange Server Subscription Edition to maintain access to ongoing security updates.
While Exchange Online customers are inherently protected against the vulnerabilities addressed in this release, businesses operating hybrid deployments must still update their on-premises Exchange servers. This includes servers used solely for management purposes, as well as machines running Exchange Management Tools, all of which require the applicable security updates.
What You Should Do
- Immediately Apply Updates: Review and apply the September 2026 V2 security updates for Exchange Server as soon as possible. Organizations that applied the initial September patch must re-apply the new V2 version.
- Utilize Health Checker: Run the Exchange Server Health Checker script to identify any missing cumulative updates, security updates, and necessary manual actions.
- Plan Upgrade Path: Use the Exchange Update Wizard to determine the correct upgrade path before installing the latest security package.
- Restart and Verify: After installation, restart the server, confirm that all Exchange services are running correctly, and then run Health Checker again to ensure all steps are complete.
- ESU Program Enrollment: For Exchange Server 2016 and 2019 users, ensure you are enrolled in Microsoft’s Period 2 Extended Security Update program or plan migration to Exchange Server Subscription Edition.
- Monitor for Known Issues: Be aware of known issues such as HTTP 500 errors with published calendar files and ContentEngine deadlocks with Korean language email. Microsoft plans to address these in future updates.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.