Microsoft releases Exchange V2 patches for authorization flaws
Authenticated attackers could access other users' mailboxes within the same organization through CVE-2026-96940, potentially exposing messages and attachments, according to Cyber Security News. Neowin reports that administrators running on-premises Exchange Server 2016 and 2019 need Period 2 ESU enrollment to obtain the V2 security updates addressing weak authorization bugs.
- Cyber Security News identifies the patches as September 2026 V2 updates.
Covered by 2 publishers within 3 hours of the first report.
Reporting2
Neowin On-premises Exchange admins must install V2 security updates · Paul Hill
Cyber Security News Microsoft Pushes New Exchange V2 Update After Discovering New Security Flaw · Guru Baran
Related
Topics Microsoft