P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Microsoft shipped September's Exchange update twice, 24 days apart, and only the second fixes CVE-2026-96940

Microsoft reissued September's Exchange security update on 2 October to add CVE-2026-96940, which lets an authenticated user read other users' mail. Three of the four affected builds are out of support and get the fix only under a paid programme that ends on 31 October.

By Parminder Kumar Sharma · · 19 min read

A racked server in a dark equipment room with a laptop on a steel trolley in front of it, the laptop showing a mailbox list of blank rows with one row picked out in a thin amber outline. A network cable runs from the server to the laptop.

Twenty-four days between two releases of one update

Microsoft released the September 2026 Exchange security update on Tuesday 8 September. On Friday 2 October it released it again as "V2", 24 days later, with one addition: CVE-2026-96940, a flaw that lets an authenticated user read other users' email and attachments. The CVE record's own build ranges treat the first release as unfixed. On Exchange Server Subscription Edition (SE), anything below build 15.02.2562.053 is listed as affected, and the September update installs 15.02.2562.049.

That is the checkable fact. It does not establish exploitation. Microsoft says it is "not aware of active exploitation", the Microsoft Security Response Center (MSRC) record's exploited field reads "No", and the CISA enrichment data on the CVE, dated 2 October, reads exploitation "none". The CVE was not in CISA's Known Exploited Vulnerabilities (KEV) catalogue, version 2026.10.04, when we read it at 15:31 BST on Monday 5 October. The fact also does not show how hard the flaw is to use, how long it has existed, or which mailboxes it reaches. And it does not date the Exchange Online fix, which Microsoft says it "already deployed" and has not dated. That last gap matters: the head start the cloud had over on-premises servers is the number a reader would most want, and nothing Microsoft has published allows it to be computed.

What the record does show is a short list of things that are not what they first look like. The reassuring sentence in the advisory is about a boundary that an on-premises organisation does not have. The severity label is not the severity score. The fix for three of the four affected builds sits behind a paid programme that ends on 31 October. And Microsoft's explanation for an odd release is one sentence long.

What the record says, and what it leaves out

Help Net Security's report, which pointed us to the primaries, calls the flaw high-severity. That is the CVSS band for a score of 8.8. Microsoft's own label is Important. Both are true, and they are not the same statement. The table separates what Microsoft, CVE.org, NVD and CISA state from what none of them does.

Stated and not stated for CVE-2026-96940. Sources: MSRC Security Update Guide record, Exchange Team blog of 2 October, CVE.org, NVD, CISA KEV; read 5 October 2026.

  1. Question
    What is the flaw?
    Stated, and by whom
    MSRC: weak authorization lets an authenticated attacker elevate privileges over a network. Its FAQ: access to other users' mailboxes in the same organisation, with email and attachments readable.
    Not stated
    Which mailboxes. Whether a role or configuration is needed. Whether anything beyond reading is possible, although the vector scores integrity and availability High.
  2. Question
    How severe?
    Stated, and by whom
    Microsoft: Important. CVSS 3.1 base 8.8, temporal 7.7, both scored by Microsoft.
    Not stated
    NVD's own view. Its record is at status Received and carries Microsoft's vector only.
  3. Question
    Has it been used?
    Stated, and by whom
    MSRC: exploited No, publicly disclosed No. Exploitability index: Exploitation More Likely. CISA enrichment, 2 October: exploitation none, automatable no, technical impact total. Not in KEV.
    Not stated
    What telemetry Microsoft checked. Whether anyone has tried since 2 October.
  4. Question
    Who found it?
    Stated, and by whom
    Blog: found internally. MSRC credits one Microsoft employee as finder.
    Not stated
    How long the flaw existed, or which release introduced it.
  5. Question
    Is Exchange Online covered?
    Stated, and by whom
    MSRC: a related service-side fix is already deployed. Blog: Exchange Online customers are already protected.
    Not stated
    The date. What related means. Whether mailbox data was exposed before the fix.
  6. Question
    What about hybrid?
    Stated, and by whom
    Blog: install the update on on-premises servers even if they are used only for management. Re-run the Hybrid Configuration Wizard if the auth certificate changes after install.
    Not stated
    Whether cloud mailboxes can be reached from an on-premises server. Whether a management-only server is exposed.
  7. Question
    Why a V2?
    Stated, and by whom
    Blog: V2 differs from the original only by the addition of this CVE. It was published ahead of its intended schedule.
    Not stated
    Why early. What the schedule was. Whether the first release is withdrawn.
  8. Question
    Is a restart needed?
    Stated, and by whom
    Blog: restart after setup completes and check services. MSRC product table: reboot required No.
    Not stated
    Which of the two is meant.

A boundary an on-premises estate does not have

The advisory says the flaw "does not allow access across tenant boundaries". Microsoft states it and nothing we read contradicts it. It protects one Exchange Online customer from another. An on-premises organisation has one Exchange organisation and no neighbouring tenant, so its whole estate sits on the inside of the line the sentence describes. Microsoft's own description of what the flaw gives is access to other users' mailboxes within the same organisation. The reassuring half of the sentence is about a boundary a single-tenant on-premises estate does not have. The half that applies, access within the organisation, describes the whole of it.

The second reassurance is the word authenticated. In the vector it is PR:L, privileges required low, alongside AV:N, AC:L and UI:N: reachable over the network, low complexity, no user interaction. The CVSS 3.1 specification defines low privileges as basic user capabilities. An ordinary mailbox login qualifies. An attacker who already holds one valid account, however it was obtained, has met the entry condition. The record does not say which accounts or which mailboxes the flaw then reaches.

Two details in Microsoft's own record do not match, and neither is explained. The description says weak authorization; the weakness field says CWE-1390, titled Weak Authentication, which MITRE defines as a mechanism that does not sufficiently prove the claimed identity. And the vector rates confidentiality, integrity and availability all High, while the FAQ describes reading mail. We flag both as unexplained, not as errors.

Then the labels. Microsoft's severity scale has four levels. Critical covers code execution without user interaction. Important covers compromise of the confidentiality, integrity or availability of user data, and Microsoft asks customers to apply Important updates "at the earliest opportunity". The label says nothing about what matters to a mail server, which is that one mailbox boundary can be crossed by another account. Cyber Essentials does not use Microsoft's label for its 14 day rule. It uses a CVSS score of 7 or above, which 8.8 meets.

The exploitability rating needs the same care. Microsoft's Exploitability Index defines "Exploitation More Likely" as an assessment that an attacker could consistently exploit the flaw, with Microsoft aware of past instances of this type of vulnerability being exploited. That is the standing definition of the rating wherever it appears. Help Net Security's report presents it as Microsoft's view of this flaw; the record states the rating, not a separate finding. The vector's temporal part says E:U, exploit code maturity unproven, which describes today; the index is the forecast. What the rating does carry is rarity. Of the nine CVEs in the V2 package, this is the only one rated More Likely; the other eight are Less Likely. And the KEV catalogue shows what "this type" can mean for Exchange: 18 Microsoft Exchange entries, four named privilege escalation and two information disclosure. None of them is this flaw. The counts are from catalogue version 2026.10.04.

What V2 changes, and what the first update still does

Microsoft's V2 blog post says the only difference between the original September release and V2 is the addition of CVE-2026-96940. The build numbers say the same thing in a form that can be checked on a server.

Exchange build numbers for the September update (V1, 8 September) and V2 (2 October). Sources: Microsoft's Exchange build numbers page; fixed builds from the MSRC affected-products list and CVE.org.

  1. Product and cumulative update
    Exchange SE RTM
    V1 build, 8 September
    15.02.2562.049
    V2 build, the fixed one
    15.02.2562.053 (KB5129955)
  2. Product and cumulative update
    Exchange 2019 CU15
    V1 build, 8 September
    15.02.1748.051
    V2 build, the fixed one
    15.02.1748.053 (KB5129956)
  3. Product and cumulative update
    Exchange 2019 CU14
    V1 build, 8 September
    15.02.1544.046
    V2 build, the fixed one
    15.02.1544.048 (KB5129957)
  4. Product and cumulative update
    Exchange 2016 CU23
    V1 build, 8 September
    15.01.2507.073
    V2 build, the fixed one
    15.01.2507.075 (KB5129958)

CVE.org lists each of the four products as affected below its V2 build. A server fully patched with the September release on 8 September is therefore, on the record, still affected. Microsoft's V2 articles say each package replaces the August update, as the September ones did, and neither names the other. Our reading, labelled as inference: for any server that needs this fix, V2 supersedes the first release in practice. Whether Microsoft has withdrawn the September packages is not stated.

The nine CVEs in the V2 package, from each MSRC record. The first eight were published on 8 September, the ninth on 2 October.

  1. CVE and Microsoft's title
    CVE-2026-96940, elevation of privilege
    CVSS base score
    8.8
    Exploitability index
    More Likely
  2. CVE and Microsoft's title
    CVE-2026-69356, spoofing
    CVSS base score
    9.3
    Exploitability index
    Less Likely
  3. CVE and Microsoft's title
    CVE-2026-69641, elevation of privilege
    CVSS base score
    9.1
    Exploitability index
    Less Likely
  4. CVE and Microsoft's title
    CVE-2026-69355, remote code execution
    CVSS base score
    8.8
    Exploitability index
    Less Likely
  5. CVE and Microsoft's title
    CVE-2026-55007, remote code execution
    CVSS base score
    8.1
    Exploitability index
    Less Likely
  6. CVE and Microsoft's title
    CVE-2026-69378, denial of service
    CVSS base score
    7.5
    Exploitability index
    Less Likely
  7. CVE and Microsoft's title
    CVE-2026-69361, spoofing
    CVSS base score
    6.5
    Exploitability index
    Less Likely
  8. CVE and Microsoft's title
    CVE-2026-69375, tampering
    CVSS base score
    6.5
    Exploitability index
    Less Likely
  9. CVE and Microsoft's title
    CVE-2026-69382, information disclosure
    CVSS base score
    5.9
    Exploitability index
    Less Likely

All nine are rated Important by Microsoft, and six of the nine score 7.0 or above. That matters for the Cyber Essentials rule on multi-issue updates, below. It also means the first release is not a minor one: it closed eight flaws, two of them remote code execution, and the V2 package adds the one with the highest exploitation rating.

V2 fixes none of the known issues: Exchange SE carries three, and 2019 and 2016 carry the first of them. Since the August update, published calendar feeds (KB5126672) return HTTP 500 to calendar applications as opposed to browsers, on Exchange SE, 2019 and 2016; Microsoft documents a workaround. Hybrid free/busy fails for delegated mailboxes in Graph-only deployments (KB5127092). Korean-language content can deadlock the content engine (KB5130098). An organisation that publishes room or meeting calendars to outside readers should read the first before it patches.

Microsoft's own pages disagree in two places. The V2 blog lists the free/busy problem under "Issues resolved in this release"; the KB5127092 article says Microsoft is still investigating it, and KB5129955 lists it as a known issue. And the KB5129955 page prints the same SHA256 for its English package as the KB5121608 page prints for the September package, a differently named file on a different build. Two different builds cannot share a hash. A German blog and a reader comment report that the Download Center shows a different value for the V2 file; we did not download the hash table and cannot confirm it. Verify the package against Microsoft's Download Center hash table, not the KB page, and tell Microsoft if two pages differ.

The rollout: what Microsoft did and did not explain

The record gives these times. The Microsoft Update Catalog lists KB5129955 with a last-updated date of 1 October. MSRC stamps the release 07:00 Pacific on 2 October, and the CVE record gives a public date of 14:00 UTC that day. The CVE record itself was published at 19:06 UTC and the Exchange Team's blog post at 19:07 UTC, 12:07 Pacific. Two admin blogs say the package appeared in Windows Server Update Services (WSUS) and Windows Update on 1 and 2 October with no article behind it, one adds that its documentation link was dead, and administrators asked what it was. That is secondary reporting; the catalogue date is ours.

Timeline to scale from 8 to 31 October 2026. V1 released 8 September. CVE ID reserved 23 September. Package listed in the Update Catalog 1 October. V2 released 2 October, 24 days after V1. CISA exploited list does not show the CVE on 5 October. Patch Tuesday 13 October. Fourteen days from 2 October is 16 October. ESU Period 2 ends 31 October, 29 days after V2.
Dates from the Microsoft Exchange Team blog, MSRC, CVE.org, the Microsoft Update Catalog, CISA KEV, NVD, Microsoft ESU posts and NCSC Cyber Essentials v3.3. The Exchange Online fix date is not published, so it is not drawn.

Microsoft's explanation is one FAQ entry, which opens by calling the release sequence "a bit strange". The update, it says, "was published ahead of its intended schedule". The post also warns that documentation "may not be fully available" when it is published. It does not say why the update was early, what the intended date was, or whether the Exchange Online fix came first by hours or by weeks. One inference, labelled as ours: MSRC files this CVE under its 2026-Oct release, and October's Patch Tuesday falls on 13 October, 11 days after 2 October. That fits an update that came early. Microsoft does not say so.

Help Net Security ties the surprise to the Exchange Online fix. The reports we found tie it to the on-premises package turning up in WSUS and Windows Update without an article. The two may be connected, and Microsoft has not said. What can be said is narrower. Microsoft states that a service-side fix was deployed, gives no date, and calls it "related" without defining the word. Cloud tenants were covered at an unknown time. On-premises administrators, on the secondary reports, found a package before they were told what it fixed. For a platform whose cloud and on-premises halves are meant to be run together, that sequence leaves a gap in the record, and this briefing records it as one.

Who can get the fix: four builds, one supported product

Four builds are named: Exchange SE RTM, 2019 CU15 and CU14, and 2016 CU23. Only one is a supported product. SE is on Microsoft's Modern Lifecycle Policy and listed as in support. Exchange 2016 and 2019 reached end of support on 14 October 2025, 356 days before this briefing. Microsoft's blog says the V2 packages for them are available only to organisations enrolled in the Period 2 Extended Security Update (ESU) programme.

Support status and the route to the fix, by build. Sources: Microsoft lifecycle pages, the V2 blog and KB articles, MSRC affected-products list.

  1. Build
    Exchange SE RTM
    Microsoft lifecycle status
    In support, Modern Lifecycle
    Where the fix comes from
    KB5129955, public Download Center and Update Catalog
  2. Build
    Exchange 2019 CU15 and CU14
    Microsoft lifecycle status
    Out of support since 14 October 2025
    Where the fix comes from
    KB5129956 and KB5129957, Period 2 ESU customers only
  3. Build
    Exchange 2016 CU23
    Microsoft lifecycle status
    Out of support since 14 October 2025
    Where the fix comes from
    KB5129958, Period 2 ESU customers only
  4. Build
    Older 2019 and 2016 CUs
    Microsoft lifecycle status
    Not named in the record
    Where the fix comes from
    Not stated whether affected. No update listed
  5. Build
    Exchange 2013
    Microsoft lifecycle status
    Out of support since 11 April 2023
    Where the fix comes from
    Not stated whether affected. No update listed
Support map to scale from January 2023 to December 2026. Exchange SE is in support from 1 July 2025 with no end date published. Exchange 2019 and 2016 were supported to 14 October 2025, then covered by paid ESU Period 1 to 14 April 2026 and Period 2 from 1 May to 31 October 2026, after which no update is listed or promised. Exchange 2013 left support on 11 April 2023.
Dates from Microsoft's lifecycle pages and the Exchange Team's ESU announcements. ESU Period 1 start is taken as the end of support date; its end date is the one in the original announcement.

Period 2 runs from the start of May to the end of October 2026, and Microsoft's announcement says there will be no further extensions. It is a separate purchase, aimed at Enterprise Agreement customers. Microsoft says it is "not committing to actually releasing any SUs" during the period, and that the ESU is not an extension of the support lifecycle: servers stay out of support. October's Patch Tuesday, 13 October, is the last scheduled one inside the window. From 5 October there are 26 days to the end. Microsoft's answer for anyone on 2016 or 2019 without the ESU is to migrate to Exchange SE. Microsoft sells the ESU and also sells the alternatives it recommends, Exchange SE and Exchange Online. That is a commercial fact, not an accusation, and the programme's terms were published in April.

The record names four builds only. It does not say whether older cumulative updates, or Exchange 2013 and earlier, are affected, and it lists no update for them. That is silence, not reassurance. A build Microsoft no longer assesses has not been found safe.

The UK record

The NCSC's Exchange pages date from 2021. In March 2021, while the flaws were being exploited at scale, it told organisations to install the latest Exchange updates "as a matter of urgency" and to search for compromise whatever their update status, and its alert said an out-of-support version should be updated to a supported one "without delay". On 14 April 2021, with "no information" suggesting active exploitation, it still recommended installing updates as soon as practicable, because attackers "may seek to build exploit capability". That is the closest NCSC precedent we found for this position: a fix, no known exploitation, and an attacker's incentive to build. At 14:37 UTC on 5 October the NCSC feed, whose newest item was dated 28 September, mentioned neither Exchange nor this CVE, and NHS England Digital's newest alert concerned NetScaler.

Cyber Essentials v3.3, dated April 2026, requires updates to be installed within 14 days of release where the vendor calls the vulnerability critical or high risk, or the CVSS v3 base score is 7 or above. The score here is 8.8. Fourteen days from the documented release on 2 October is 16 October; from the catalogue date of 1 October it is 15 October. An update that covers several issues must be installed within 14 days if it covers any high-risk issue, and six of the nine CVEs in this package score 7 or above. Microsoft's Important label uses neither of the rule's words. The score does.

The same document requires software to be "licensed and supported", and removed from devices or from scope when it becomes unsupported. Microsoft says its ESU is not an extension of the support lifecycle. We found no NCSC statement on whether Period 2 ESU counts as supported for an assessor, so that is a question for the certification body, not an assumption.

We found no public count of UK organisations that still run on-premises or hybrid Exchange, so the exposure is unmeasured here. What can be said is what such an estate holds: whatever the organisation emails. For a council, a law firm, a health body or a school that is personal data, and a flaw that only reads is still a confidentiality incident if it is used. The ICO says that where a risk to people is likely a personal data breach must be reported as soon as possible and, where feasible, within 72 hours. US CISA and NSA published Exchange hardening guidance on 30 October 2025 with international partners; it is not NCSC guidance; it strongly encourages proactive steps for end-of-life versions, and CISA's release recommends evaluating cloud email.

Readers who want the wider pattern of Microsoft labels and exploited-flaw clocks can read the earlier briefings on SharePoint CVE-2026-65660, where a spoofing label hid code execution, on September's KEV three day deadlines, and on a third NetScaler flaw labelled denial of service. For another on-premises mail server whose patch preceded its CVE ID, see the Zimbra briefing.

What to do, in the order worth doing

The order puts knowing what you run before patching it, and entitlement before either for the two out-of-support lines. Items marked judgement are ours, not Microsoft's.

Take this with you

Checklist for an on-premises or hybrid Exchange estate

  • Inventory every Exchange server and every machine running the Exchange Management Tools, including servers kept only for hybrid management, with each build number. Microsoft's Exchange Server Health Checker script reports builds and missing updates.
  • Compare each build with the fixed one: 15.02.2562.053 on Exchange SE, 15.02.1748.053 on 2019 CU15, 15.02.1544.048 on 2019 CU14, 15.01.2507.075 on 2016 CU23. A server on the September build is not fixed. A server on an older cumulative update needs the update first.
  • For Exchange 2016 and 2019, confirm whether the organisation holds the Period 2 ESU and has the V2 package. If not, there is no fix available to you. Set a dated migration to Exchange SE, because Period 2 ends on 31 October and Microsoft says it will not be extended.
  • Read the three known issues before patching, above all the published calendar problem if the organisation publishes calendars to outside readers. Patch one server first if the estate allows.
  • Install the V2 update by the route Microsoft documents for security updates. Its packaging notes say the installer needs elevated permissions and that the self-elevating .exe suits manual installs. Do not assume an automatic approval in WSUS or Windows Update has done the job: check the build number afterwards.
  • Verify the downloaded package against the hash table on Microsoft's Download Center, not the hash printed on the KB5129955 page, which matches the September package. Tell Microsoft if two pages disagree.
  • In a hybrid deployment, patch the on-premises servers even though Exchange Online is covered, and re-run the Hybrid Configuration Wizard if the auth certificate changes after installation, as Microsoft's FAQ says.
  • Judgement: look back as well as forward. Review mailbox audit logs and web server logs for one account reading other users' mailboxes since at least 8 September. Know the limits: Microsoft's page describes enabling mailbox auditing per mailbox in PowerShell, owner actions are not logged by default, and entries are kept for 90 days by default, which reaches back only to 7 July. Whether this flaw leaves any mailbox audit record is not stated.
  • Judgement: treat the precondition as the control. The attacker needs a valid account, so review sign-in anomalies and password spraying against OWA, ActiveSync and EWS, and require multi-factor authentication for anything reachable from outside.
  • Record the decision and the date for Cyber Essentials: installed by 15 October to be safe, 16 October at the latest on Microsoft's documented release date.
  • Watch the four pages that can change under you: the MSRC record, the update list at the foot of the Exchange Team post, the CISA KEV catalogue and the NCSC alert feed.

What we could not verify

The question this leaves

Microsoft's reassurance is about a boundary between tenants. In a one-tenant estate the boundary that matters is the one between the weakest mailbox account and the most sensitive mailbox on the same server, and the record says this flaw can cross a boundary of that kind, without saying which accounts or which mailboxes. Microsoft says the flaw does not cross a tenant boundary. Which boundary does it cross on your estate, and which log would show it?

Key facts

Sources

  1. PrimaryReleased: September 2026 V2 Exchange Server Security Updates, read in full: published 2 October 2026 12:07 Pacific, affected versions, ESU condition, FAQ on hybrid, on management tools and on the release sequenceMicrosoft Exchange Team blogaccessed 2026-10-05
  2. PrimaryReleased: September 2026 Exchange Server Security Updates (V1, 8 September 2026), read in full, for what V2 changesMicrosoft Exchange Team blogaccessed 2026-10-05
  3. PrimarySecurity Update Guide record for CVE-2026-96940, read as JSON from the guide's API: description, CVSS vector 3.1 base 8.8 temporal 7.7, Important, Exploitation More Likely, exploited No, FAQ, revision, acknowledgement and the four affected products with fixed buildsMicrosoft Security Response Centeraccessed 2026-10-05
  4. PrimaryKB5129955, V2 update for Exchange SE RTM, 2 October 2026: nine CVEs, known issues, replaced update, hashMicrosoft Supportaccessed 2026-10-05
  5. PrimaryKB5129956, V2 update for Exchange 2019 CU15: CVEs, ESU note, one known issueMicrosoft Supportaccessed 2026-10-05
  6. PrimaryKB5129957, V2 update for Exchange 2019 CU14Microsoft Supportaccessed 2026-10-05
  7. PrimaryKB5129958, V2 update for Exchange 2016 CU23Microsoft Supportaccessed 2026-10-05
  8. PrimaryKB5121608, September 2026 update for Exchange SE RTM (V1): eight CVEs, known issues, replaced update, hashMicrosoft Supportaccessed 2026-10-05
  9. PrimaryKB5126672, published calendar (.ics) HTTP 500 after the August 2026 update, and its workaroundMicrosoft Supportaccessed 2026-10-05
  10. PrimaryKB5127092, free/busy fails for delegated mailboxes in Graph-only hybrid: Microsoft is investigatingMicrosoft Supportaccessed 2026-10-05
  11. PrimaryKB5130098, ContentEngine deadlock with missing Korean WordBreaker rule filesMicrosoft Supportaccessed 2026-10-05
  12. PrimarySecurity Update for Exchange Server SE RTM SU10v2 (KB5129955): version 15.02.2562.053, date published 10/2/2026Microsoft Download Centeraccessed 2026-10-05
  13. PrimaryCatalogue listing for KB5129955: last updated 10/1/2026, 341.4 MBMicrosoft Update Catalogaccessed 2026-10-05
  14. PrimaryExchange Server build numbers and release dates: V1 and V2 builds for SE, 2019 CU15 and CU14, 2016 CU23Microsoft Learnaccessed 2026-10-05
  15. PrimaryLifecycle page for Exchange SE: Modern Lifecycle Policy, in support since 1 July 2025Microsoft Learnaccessed 2026-10-05
  16. PrimaryLifecycle page for Exchange 2019: Fixed Lifecycle Policy, extended support end 14 October 2025Microsoft Learnaccessed 2026-10-05
  17. PrimaryLifecycle page for Exchange 2013: extended support end 11 April 2023Microsoft Learnaccessed 2026-10-05
  18. PrimarySupport for Exchange 2016 and 2019 ends today, 14 October 2025Microsoft Exchange Team blogaccessed 2026-10-05
  19. PrimaryPeriod 2 ESU announcement, 15 April 2026: May to October 2026, no further extensions, no commitment to release updatesMicrosoft Exchange Team blogaccessed 2026-10-05
  20. PrimaryOriginal ESU announcement, 15 July 2025: Period 1 through 14 April 2026, updates provided privatelyMicrosoft Exchange Team blogaccessed 2026-10-05
  21. PrimaryNew Exchange Server security update and hotfix packaging: elevated permissions, .msp and .exe packagesMicrosoft Exchange Team blogaccessed 2026-10-05
  22. PrimaryExploitability Index definitions, including Exploitation More LikelyMicrosoft Security Response Centeraccessed 2026-10-05
  23. PrimarySecurity Update Severity Rating System: Critical, Important, Moderate, LowMicrosoft Security Response Centeraccessed 2026-10-05
  24. PrimaryCVE record read as JSON from the CVE Services API: dateReserved 23 September 2026 20:35 UTC, published 2 October 19:06 UTC, affected build ranges, CISA-ADP SSVC containerCVE.orgaccessed 2026-10-05
  25. PrimaryNVD record read through the API at 14:31 UTC on 5 October 2026: status Received, Microsoft's CVSS vector as secondary source, CISA-ADP SSVC dataNIST National Vulnerability Databaseaccessed 2026-10-05
  26. PrimaryKEV JSON, catalogue version 2026.10.04, released 18:52 UTC on 4 October, 1,734 entries: CVE-2026-96940 absent; 18 Microsoft Exchange entries countedCISAaccessed 2026-10-05
  27. PrimaryCWE-1390: Weak Authentication, definitionMITREaccessed 2026-10-05
  28. PrimaryCVSS 3.1 specification: Privileges Required Low definition and scoringFIRSTaccessed 2026-10-05
  29. PrimaryUpdate for organisations on Microsoft Exchange Server vulnerabilities, 12 March 2021NCSCaccessed 2026-10-05
  30. PrimaryMicrosoft vulnerabilities exploitation, updated advice, 12 March 2021: out-of-support versions, search for compromiseNCSCaccessed 2026-10-05
  31. PrimarySecurity updates released for Microsoft Exchange Servers, 14 April 2021NCSCaccessed 2026-10-05
  32. PrimaryCyber Essentials Requirements for IT Infrastructure v3.3, April 2026: 14 day rule, CVSS 7 threshold, licensed and supported softwareNCSCaccessed 2026-10-05
  33. PrimaryNCSC alert and news feed read at 14:37 UTC on 5 October 2026: newest item 28 September, nothing on ExchangeNCSCaccessed 2026-10-05
  34. PrimaryCyber alerts list read on 5 October 2026: newest CC-4862 on NetScaler, nothing on ExchangeNHS England Digitalaccessed 2026-10-05
  35. PrimaryPress release of 30 October 2025 on the Microsoft Exchange Server Security Best Practices guidanceCISAaccessed 2026-10-05
  36. PrimaryReporting a personal data breach: notify as soon as possible and where feasible within 72 hoursICOaccessed 2026-10-05
  37. PrimaryMailbox audit logging in Exchange Server: enabled per mailbox, owner actions not logged by default, 90 day retentionMicrosoft Learnaccessed 2026-10-05
  38. Reported byReport of 5 October 2026 that pointed to the primaries; its framing of the Exchange Online fix and the exploitation wording is checked against themHelp Net Securityaccessed 2026-10-05
  39. Reported byReader reports of KB5129955 appearing in WSUS on 2 October with no documentation; secondaryBorns IT- und Windows-Blogaccessed 2026-10-05
  40. Reported byFollow-up of 2 October on the four KB articles and the nine CVEs; secondaryBorns IT- und Windows-Blogaccessed 2026-10-05
  41. Reported byReport of 2 October that KB5129955 was distributed on 1 October via Update Catalog, WSUS and Windows Update with a broken KB link; secondaryFranky's Webaccessed 2026-10-05
  42. Reported byFollow-up with a reader comment on the SHA256 mismatch; secondaryFranky's Webaccessed 2026-10-05
  43. Reported byGerman-language analysis of 3 October noting the repeated SHA256 on the KB page; secondary and not verifiedGrams ITaccessed 2026-10-05

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.