Microsoft releases Exchange V2 patches for authorization flaws

First reported by Neowin at · Updated · 2 sources

Authenticated attackers could access other users' mailboxes within the same organization through CVE-2026-96940, potentially exposing messages and attachments, according to Cyber Security News. Neowin reports that administrators running on-premises Exchange Server 2016 and 2019 need Period 2 ESU enrollment to obtain the V2 security updates addressing weak authorization bugs.

  • Cyber Security News identifies the patches as September 2026 V2 updates.

Covered by 2 publishers within 3 hours of the first report.

Reporting2

Related

Topics Microsoft