The Exchange product group released an update for the September 2026 updates for Exchange Server SE, Exchange 2019, and Exchange 2016. The Security Update for Exchange SE is publicly available. Security updates for Exchange 2019 and Exchange 2016 are available to organizations enrolled in the Extended Security Update Period 2 program.
The vulnerability addressed in these V2 Security Updates for Exchange Server is:
| Vulnerability | Category | Severity | Rating |
|---|---|---|---|
| CVE-2026-96940 | Elevation of Privilege | Important | CVSS:3.1 8.8 / 7.7 |
To clarify: The V2 security updates address this CVE in addition to the CVE addressed by the original September Security Updates. Known Issues and Fixed Issues from the original September Security Updates also apply to V2.
The V2 Security Updates for each supported Exchange Server build are linked below:
| Exchange | HU/Su | Download | Build | KB | Supersedes |
|---|---|---|---|---|---|
| Exchange SE | 10v2 | Download | 15.2.2562.53 | KB5129955 | KB5121608 |
| Exchange 2019 CU15 | 11v2 | ESU2 | 15.2.1748.53 | KB5129956 | KB5121609 |
| Exchange 2019 CU14 | 14v2 | ESU2 | 15.2.1544.48 | KB5129957 | KB5121610 |
| Exchange 2016 CU23 | 25v2 | ESU2 | 15.1.2507.75 | KB5129958 | KB5121611 |
Known Issues
Notes
- Security updates are specific to the Cumulative Update level. You cannot apply the Exchange 2019 CU15 security update to Exchange 2019 CU14. When downloading, the security update might carry the same name for different Cumulative Updates. Microsoft now includes the KB article number as a reference, but I still tag the filename with the CU level for archival purposes, e.g., Exchange2019-CU15-KBxxxxxxx-x64-en.exe.
- Like Cumulative Updates, Security Updates are cumulative, and you only need to install the latest SU for your CU.
- Suppose you have deployed Exchange Management Tools to manage your on-premises Exchange Servers or installed the tools after removing the Last Exchange Server for recipient management. We recommend applying the Security Update.
Finally, as with any patch or update, test it in a test environment before deploying it to production. However, we do not recommend waiting for regular maintenance cycles for security updates; a more agile approach is preferable, and the ratings indicate the urgency level.

You must be logged in to post a comment.