Site icon TheCyberThrone

Microsoft Releases Out-of-Band Exchange Security Update

Advertisements

Executive Summary

Microsoft has released an out-of-band security update for Exchange Server to address CVE-2026-96940, an Elevation of Privilege vulnerability that could allow an authenticated attacker to access email and attachments belonging to other users within the same Exchange organization.

Microsoft says it is not aware of active exploitation of the vulnerability. However, the company released the fix outside its normal update cycle and recommends applying it at the earliest opportunity.

CVE-2026-96940

CVE-2026-96940 affects Microsoft Exchange Server and could allow an authenticated attacker to gain access to mailbox data belonging to other users.

The potential exposure includes:

The attacker must already be authenticated, and the vulnerability does not provide cross-tenant access.

Microsoft discovered the issue internally and has not reported active exploitation at this time.

Why an Out-of-Band Update?

Microsoft normally releases Exchange security updates as part of its regular servicing cycle.

This vulnerability received an out-of-band fix, indicating that Microsoft considers timely remediation important enough not to wait for the next regular update cycle.

Exchange servers remain attractive targets because they contain large amounts of sensitive organizational information. A vulnerability that can cross normal mailbox access boundaries therefore deserves prompt attention, even without confirmed exploitation.

Affected Versions

The update applies to:

Microsoft has also released V2 versions of the relevant security updates.

Key updates include:

Organizations should verify that they have installed the latest applicable update rather than relying on the original package.

Exchange 2016 and 2019 Consideration

Exchange Server 2016 and Exchange Server 2019 are already out of mainstream support.

Security updates remain available to eligible organizations through Microsoft’s Extended Security Update (ESU) program. Organizations still operating these versions should use this period to accelerate migration toward Exchange Server Subscription Edition.

Post-Update Checks

Microsoft has documented some issues that administrators should consider after deployment, including problems involving published calendars and certain hybrid free/busy scenarios.

After installing the update, administrators should:

  1. Verify the Exchange build number.
  2. Run the Exchange Server Health Checker.
  3. Confirm mail flow.
  4. Test Outlook, OWA and ECP access.
  5. Validate calendar functionality.
  6. Check hybrid free/busy functionality where applicable.
  7. Review Exchange logs and authentication activity for unusual behavior.

What Security Teams Should Do

Organizations running on-premises Exchange should treat this as a high-priority patching activity.

Start by identifying all Exchange servers and their current builds. Prioritize externally accessible systems, apply the appropriate V2 security update, and validate the environment after installation.

Although there is currently no confirmed exploitation, the combination of authenticated access, potential mailbox data exposure and Microsoft’s decision to issue an out-of-band fix makes this a vulnerability worth addressing quickly.

For Exchange administrators, this is not a patch to leave in the backlog.

Exit mobile version