Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical GitLab AI Gateway RCE Vulnerability CVE-2024-4835 Patched
October 3, 2026
Microsoft Patches Critical Exchange Server Vulnerability CVE-2023-21763
October 3, 2026
Critical Dell Container Storage CVE-2024-29001 Flaws Let Attackers Gain Admin Control
October 3, 2026
Home/CyberSecurity News/Microsoft Patches Critical Exchange Server Vulnerability CVE-2023-21763
CyberSecurity News

Microsoft Patches Critical Exchange Server Vulnerability CVE-2023-21763

Key Takeaways Microsoft has issued an urgent V2 security update for Exchange Server to address a critical vulnerability. The flaw, CVE-2026-96940, allows authenticated attackers to access other...

Emy Elsamnoudy
Emy Elsamnoudy
October 3, 2026 3 Min Read
2 0

Key Takeaways

  • Microsoft has issued an urgent V2 security update for Exchange Server to address a critical vulnerability.
  • The flaw, CVE-2026-96940, allows authenticated attackers to access other users’ mailboxes within the same organization.
  • Rated 8.8 CVSS, it does not require user interaction for exploitation.
  • The fix is available in the September 2026 V2 security updates, and organizations that applied the initial September patch must re-apply the new version.
  • Exchange Server 2016 and 2019 users require an Extended Security Update (ESU) program subscription.

Microsoft Addresses Critical Exchange Server Mailbox Access Flaw

Microsoft has released an out-of-band V2 security update for Exchange Server, patching a critical vulnerability designated CVE-2026–96940. This flaw could enable authenticated attackers to gain unauthorized access to other users’ mailboxes within the same organizational network, posing a significant risk to on-premises Exchange deployments by potentially exposing sensitive email content and attachments.

Table Of Content

  • Key Takeaways
  • Microsoft Addresses Critical Exchange Server Mailbox Access Flaw
  • Reissued Update for Enhanced Protection
  • Extended Security Update Program and Hybrid Deployments
  • What You Should Do

The vulnerability stems from an authorization weakness, allowing an authenticated network attacker to elevate privileges. With a CVSS score of 8.8, the severity is considerable. Importantly, exploiting this flaw does not necessitate any user interaction, distinguishing it from many other attack vectors that rely on a user opening a malicious file. Microsoft has clarified that the reported mailbox access is confined to within an organization and does not extend across different tenant boundaries.

According to Microsoft, their internal teams discovered this vulnerability, and there is currently no evidence of active exploitation in the wild. The company also noted that this update was released ahead of its originally scheduled deployment, which might have resulted in some supporting documentation not being immediately available upon the announcement.

Reissued Update for Enhanced Protection

The September 2026 V2 release specifically incorporates protections against CVE-2026-96940, building upon the initial September security updates. Consequently, organizations that previously installed the earlier September release are strongly advised to review and apply these new packages to ensure comprehensive protection, rather than assuming their systems are already secure against this particular vulnerability.

Updates are available for Exchange Server Subscription Edition RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23. Administrators must carefully select the specific update package that corresponds to their installed Exchange Server version and cumulative update level.

This new vulnerability, CVE-2026-96940, is distinct from CVE-2026-62911, an earlier Exchange vulnerability that garnered attention after a public proof of concept demonstrated an authentication relay attack. It is crucial not to conflate the two; the existence of an exploit for CVE-2026-62911 does not imply an exploit for CVE-2026-96940.

Extended Security Update Program and Hybrid Deployments

For Exchange Server 2016 and 2019, which are now out of mainstream support, the latest patches are exclusively available to organizations participating in Microsoft’s Period 2 Extended Security Update program. This program covers security updates from May through October 2026.

Enrollment in Period 2 requires a separate purchase, even for customers who participated in the earlier ESU program. Microsoft has stated that no further extensions will be offered beyond October. Organizations without current ESU coverage should prioritize migrating to Exchange Server Subscription Edition to maintain access to ongoing security updates.

While Exchange Online customers are inherently protected against the vulnerabilities addressed in this release, businesses operating hybrid deployments must still update their on-premises Exchange servers. This includes servers used solely for management purposes, as well as machines running Exchange Management Tools, all of which require the applicable security updates.

What You Should Do

  • Immediately Apply Updates: Review and apply the September 2026 V2 security updates for Exchange Server as soon as possible. Organizations that applied the initial September patch must re-apply the new V2 version.
  • Utilize Health Checker: Run the Exchange Server Health Checker script to identify any missing cumulative updates, security updates, and necessary manual actions.
  • Plan Upgrade Path: Use the Exchange Update Wizard to determine the correct upgrade path before installing the latest security package.
  • Restart and Verify: After installation, restart the server, confirm that all Exchange services are running correctly, and then run Health Checker again to ensure all steps are complete.
  • ESU Program Enrollment: For Exchange Server 2016 and 2019 users, ensure you are enrolled in Microsoft’s Period 2 Extended Security Update program or plan migration to Exchange Server Subscription Edition.
  • Monitor for Known Issues: Be aware of known issues such as HTTP 500 errors with published calendar files and ContentEngine deadlocks with Korean language email. Microsoft plans to address these in future updates.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVECybersecurityExploitPatchSecurityVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical Dell Container Storage CVE-2024-29001 Flaws Let Attackers Gain Admin Control

Next Post

Critical GitLab AI Gateway RCE Vulnerability CVE-2024-4835 Patched

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Microsoft SQL Server Vulnerability Lets Attackers Exfiltrate Data
October 2, 2026
Critical Flaws in JetBrains TeamCity Let Attackers Steal Credentials
October 2, 2026
Critical cPanel & WHM Flaws Let Attackers Run Commands
October 2, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us