Microsoft has re-released its September 2026 Exchange Server security updates with one more fix in them. The V2 build adds CVE-2026-96940, so servers that took the first September build do not have it.
In a post on the Exchange Team Blog dated Oct. 2, Microsoft says the only difference between the original September release and V2 is the addition of CVE-2026-96940. The updates cover Exchange Server Subscription Edition RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23. The 2019 and 2016 builds go only to organizations enrolled in the Period 2 Extended Security Update program, because both versions are out of support.
Microsoft says Exchange Online customers are already protected. Hybrid organizations still need the update on their Exchange servers, including servers used only for management. Microsoft recommends installing it on every Exchange server and every machine running the Exchange Management Tools. The updates are cumulative, so a server on a supported cumulative update needs only the latest one. Two known issues are listed: published calendar (.ics) files can return HTTP 500, and content indexing can deadlock for Korean-language mail. Both are due to be fixed in a future update.
Why it matters: the blog post points to the download KB article and the Security Update Guide for CVE details, so the severity and exploitation status of CVE-2026-96940 sit in those documents. Read them before you set a deadline.
Our read: a re-release that keeps the September name makes it easy to mark a server patched when it is not. Microsoft names the Exchange Server Health Checker script as the way to see which servers are behind on updates, and running it is the quickest way to find the gap. The timing lesson matches Start the Patch Clock on Release Day, Not Advisory Day, and mail servers have drawn early attacker attention before, as in Attackers Probed Mail Servers Between a Zimbra Fix and Disclosure.
Source: Microsoft Exchange Team Blog: Released: September 2026 V2 Exchange Server Security Updates