CVE-2026-96940 Microsoft Exchange patch — Apply Now
CVE-2026-96940 Microsoft Exchange patch: Apply the CVE-2026-96940 Microsoft Exchange patch now. Microsoft issued an out-of-band V2 Exchange update (Oct 2, 2026…

View article sections
- 01Quick summary: who should act and when
- 02What CVE-2026-96940 is and how it works
- 03Risk assessment and immediate mitigations
- 04Step‑by‑step deployment checklist
- 05Possible problems, compatibility, and rollback notes
- 06Who should prioritize this patch most urgently
- 07Alternatives if you can’t patch immediately
- 08Official references and advisories
- 09Practical checklist for small businesses (one‑page)
- 10Final takeaways
- 11Sources
- 12Related guides and resources
- 13Frequently asked questions
- 14Need practical help?
- 15Topic in context
- 16Sources and further reading
CVE-2026-96940 Microsoft Exchange patch is the focus of this dated, source-based update. As a result, the article separates verified details from analysis.
What changed and why it matters: On October 2, 2026, Microsoft released a version 2 out-of-band security update to fix a high-severity privilege‑escalation vulnerability tracked as CVE-2026-96940. This flaw can allow an authenticated low‑privilege Exchange user to access other mailboxes in the same organization, so on‑premises Exchange administrators and small to midsize businesses must review and apply the update without delay [1][2]. (Confirmed: Microsoft Support and the Exchange team.)
In this guide you will find what systems are affected, how to prioritize, step‑by‑step mitigation and deployment checklist, verification steps, and practical rollback and testing notes. Recommendations and context are analysis and practical guidance from this reporter, based on official Microsoft guidance and government advisory notes [1][2][3].
Quick summary: who should act and when
- What happened: Microsoft published the V2 September Exchange Server security updates on Oct 2, 2026 to address CVE-2026-96940 [1][2]. (Official announcement.)
- Who should act: Any organization running on-premises Microsoft Exchange Server builds covered by the update, especially those using Subscription Edition or RTM builds. Small businesses and local IT teams must prioritize this patch. (Confirmed by Microsoft.)
- When to act: Immediately. Apply the V2 update following Microsoft’s deployment guidance as soon as you can safely schedule it [1][2].
What CVE-2026-96940 is and how it works
Officially, CVE-2026-96940 is a privilege‑escalation vulnerability in Microsoft Exchange Server that can permit an authenticated low‑privilege Exchange user to read or access other mailboxes in the same organization. Microsoft lists the vulnerability and fixes in its October 2 V2 security update documentation [1][2]. (Confirmed: Microsoft Support and Exchange team posts.)
For clarity: this is not a remote unauthenticated code‑execution zero‑day. Instead, an attacker needs a valid Exchange account in the target organization. However, because it allows cross‑mailbox access, it can expose sensitive internal mail if exploited. Therefore, the practical impact is high for organizations where many users have accounts but not strict mailbox access controls.
CVE-2026-96940 Microsoft Exchange patch: affected versions
As of Oct 2, 2026, Microsoft’s V2 security update covers supported Exchange Server builds listed in its update KB and the Exchange team blog. Confirm your specific build number against Microsoft’s table before deployment [1][2]. (Official guidance.)
| Exchange edition / build | Affected? | Patch availability |
|---|---|---|
| Exchange Server Subscription Edition RTM | Yes | V2 update (KB5129955) released Oct 2, 2026 [1] |
| Other supported Exchange builds (see KB) | Possibly; confirm on KB | V2 updates posted — check Microsoft table and Exchange blog [1][2] |
Risk assessment and immediate mitigations
Confirmed facts: Microsoft classifies this vulnerability as high‑severity and released the V2 update to address it [1][2]. The Canadian Centre for Cyber Security also issued an advisory referencing Microsoft’s update and advising patching [3].
In addition to patching, follow these immediate mitigations while you schedule deployment:
- Audit mailbox permissions for excessive FullAccess or SendAs delegations.
- Enforce multi‑factor authentication (MFA) for all Exchange accounts where possible.
- Monitor Exchange logs and abnormal mailbox access patterns, for example cross‑mailbox reads from unusual accounts.
- Restrict administrative and service accounts; use least privilege principles.
These mitigations reduce exploitation risk but do not replace installing the CVE-2026-96940 Microsoft Exchange patch. Therefore, they should be temporary until the update is applied.
Step‑by‑step deployment checklist
Follow Microsoft’s guidance in the KB and Exchange team post when applying the update [1][2]. Below is a concise, practical checklist for small businesses and on‑prem admins.
- Inventory: Record Exchange build/version and server roles. Compare to Microsoft’s affected list [1].
- Back up: Take full system and database backups. Verify backup integrity and retention before updating.
- Schedule maintenance window: Notify users and stakeholders ahead of downtime windows.
- Test on staging: If possible, apply the V2 update to a test server that mirrors production.
- Apply the V2 update: Use Microsoft’s update packages or cumulative update channel as directed in KB5129955 [1].
- Restart services: Follow post‑update steps in the KB to safely restart IIS and Exchange services.
- Verify: Confirm server build number post‑patch and validate mailbox access controls.
- Monitor: Review logs for unusual access and verify normal mail flow and features.
Note: These steps are practical guidance and analysis based on Microsoft’s official updates. Always follow your organization’s change control and backup policies.
How to verify the CVE-2026-96940 Microsoft Exchange patch is applied
- Check the server build and KB number in Exchange Management Shell or Admin Center. Microsoft’s KB lists exact builds fixed by the V2 update [1].
- Confirm service health and that mail flow and OWA/EAS clients function normally.
- Run post‑patch permission audits to ensure previous misconfigurations are still unchanged.
Possible problems, compatibility, and rollback notes
Microsoft’s V2 updates are cumulative but can introduce compatibility issues with third‑party agents, antivirus, or monitoring tools. Therefore, test updates in a lab environment if available [1][2].
If you must roll back, restore from verified backups. However, rolling back a security fix can reintroduce the vulnerability. Thus, rollback should only be used for severe compatibility failures, followed quickly by remediation or vendor fixes.
Who should prioritize this patch most urgently
- Organizations with many low‑privilege accounts but broadly open mailbox delegations.
- Businesses in regulated industries (healthcare, finance, legal) where mailbox exposure risks compliance and data breach costs.
- SMBs with on‑prem Exchange managed in‑house without immediate Microsoft 365 migration plans.
For cloud Exchange (Microsoft 365), Microsoft manages server updates. This advisory concerns on‑premises Exchange Server installs. Confirm which environment you run before planning action.
Alternatives if you can’t patch immediately
If immediate patching is impossible, take layered mitigations:
- Harden mailbox permissions and remove unnecessary FullAccess delegations.
- Require and enforce MFA for all Exchange accounts.
- Implement stricter network segmentation for Exchange servers and limit administrative access to trusted IPs only.
- Increase logging, alerting and SIEM rules for cross‑mailbox access patterns and abnormal service account behavior.
These steps are temporary risk‑reduction measures. They are not substitutes for applying the CVE-2026-96940 Microsoft Exchange patch.
Comparison: Patching now vs delaying
| Action | Benefit | Tradeoffs / risks |
|---|---|---|
| Patch now (apply V2 update) | Removes known privilege‑escalation vector; reduces breach risk [1][2] | Potential compatibility testing needed; short maintenance window |
| Delay patch | More time to test in complex environments | Increased exposure; exploitation possible for authenticated insiders or compromised accounts [1][3] |
Official references and advisories
Official Microsoft details for the V2 security update (KB5129955) and the Exchange team blog describe the fixes and deployment guidance. (Official: Microsoft Support and Tech Community posts) [1][2]. The Canadian Centre for Cyber Security issued an advisory recommending prompt patching on Oct 5, 2026 [3].
As of Oct 9, 2026, these are the confirmed sources to consult for authoritative instructions: Microsoft Support KB5129955 and the Exchange team blog post [1][2].
Practical checklist for small businesses (one‑page)
- Confirm on‑premise Exchange build number today. (If unsure, contact your IT provider.)
- Back up Exchange databases and system state now.
- Apply the V2 update per KB5129955 during a maintenance window. [1]
- Verify mailbox access control and monitor logs for abnormal access.
- If you lack internal skills, schedule a vendor or MSP to apply the update.
Fixit Solutions Inc. provides local on‑site and remote assistance for SMBs in the Lake Forest, CA area, including help with Exchange patching and verification. Contact support@xfixit.com or call +1-878-787-6642 for help. (Business contact from company profile.)
Final takeaways
Microsoft issued the out‑of‑band V2 update on Oct 2, 2026 to address CVE-2026-96940. This vulnerability allows authenticated low‑privilege users to access other mailboxes in the organization and therefore presents a high practical risk for on‑prem Exchange environments [1][2]. (Confirmed by Microsoft.)
Apply the CVE-2026-96940 Microsoft Exchange patch as soon as feasible. Meanwhile, use the listed mitigations to reduce exploitation risk. If you need help, consider engaging a qualified MSP or system administrator to ensure the update is applied correctly and tested.
Sources
- Microsoft Support: Description of version 2 of the security update for Microsoft Exchange Server Subscription Edition RTM October 2, 2026 (KB5129955) [1].
- Microsoft Tech Community: Released: September 2026 V2 Exchange Server Security Updates (Exchange team) [2].
- Canadian Centre for Cyber Security: Microsoft security advisory (AV26-1001) [3].
Frequently asked questions
What is the CVE-2026-96940 Microsoft Exchange patch?
The CVE-2026-96940 Microsoft Exchange patch refers to Microsoft’s V2 security update released on Oct 2, 2026 that fixes a high‑severity privilege‑escalation flaw in on‑premises Exchange Server, which could let an authenticated low‑privilege user access other mailboxes [1][2]. (Confirmed: Microsoft Support.)
Who needs to apply the CVE-2026-96940 Microsoft Exchange patch?
Organizations running on‑premises Microsoft Exchange Server builds covered by Microsoft’s V2 update should apply the patch. Cloud Microsoft 365 customers receive server updates from Microsoft. Check your server build against KB5129955 to confirm applicability [1][2].
Can an attacker exploit CVE-2026-96940 remotely without valid credentials?
No. CVE-2026-96940 requires an authenticated Exchange account in the target organization. However, because the flaw permits cross‑mailbox access, a compromised low‑privilege account can lead to serious data exposure. Therefore patching is urgent [1][2].
What should I do if I cannot patch immediately?
If you cannot patch immediately, tighten mailbox permissions, enforce MFA, restrict administrative access to trusted IPs, and increase monitoring for suspicious mailbox access. These measures reduce risk but do not replace installing the CVE-2026-96940 Microsoft Exchange patch as soon as possible.
How do I confirm the update was installed successfully?
Verify the server build and applied KB number in Exchange Management Shell or the Admin Center. Confirm normal mail flow, test mailbox access behavior, and review logs for anomalies. Microsoft’s KB lists exact fixed builds for verification [1].
Need practical help?
Fixit Solutions Inc. — Contact Fixit Solutions today to request a free estimate, schedule a repair or discuss your business technology needs. Service area: Lake Forest, CA.
Topic in context

Sources and further reading
These links were validated and checked when possible when this article was created; some publishers limit automated requests. Facts, guidance, prices, regulations, and availability can change.
- Description of version 2 of the security update for Microsoft Exchange Server Subscription Edition RTM October 2, 2026 (KB5129955) — Microsoft Support (2026-10-02) — primary source
- Released: September 2026 V2 Exchange Server Security Updates — Microsoft Tech Community (Exchange Team) (2026-10-02) — primary source
- Microsoft security advisory (AV26-1001) — Canadian Centre for Cyber Security (Government of Canada) (2026-10-05)

