V2 Security Updates Exchange 2016-SE (Sep2026)

The Exchange product group released an update for the September 2026 updates for Exchange Server SE, Exchange 2019, and Exchange 2016. The Security Update for Exchange SE is publicly available. Security updates for Exchange 2019 and Exchange 2016 are available to organizations enrolled in the Extended Security Update Period 2 program.

The vulnerability addressed in these V2 Security Updates for Exchange Server is:

VulnerabilityCategorySeverityRating
CVE-2026-96940Elevation of PrivilegeImportantCVSS:3.1 8.8 / 7.7

To clarify: The V2 security updates address this CVE in addition to the CVE addressed by the original September Security Updates. Known Issues and Fixed Issues from the original September Security Updates also apply to V2.

The V2 Security Updates for each supported Exchange Server build are linked below:

ExchangeHU/SuDownloadBuildKBSupersedes
Exchange SE10v2Download15.2.2562.53KB5129955KB5121608
Exchange 2019 CU1511v2ESU215.2.1748.53KB5129956KB5121609
Exchange 2019 CU1414v2ESU215.2.1544.48KB5129957KB5121610
Exchange 2016 CU2325v2ESU215.1.2507.75KB5129958KB5121611

Known Issues

Notes

  • Security updates are specific to the Cumulative Update level. You cannot apply the Exchange 2019 CU15 security update to Exchange 2019 CU14. When downloading, the security update might carry the same name for different Cumulative Updates. Microsoft now includes the KB article number as a reference, but I still tag the filename with the CU level for archival purposes, e.g., Exchange2019-CU15-KBxxxxxxx-x64-en.exe.
  • Like Cumulative Updates, Security Updates are cumulative, and you only need to install the latest SU for your CU.
  • Suppose you have deployed Exchange Management Tools to manage your on-premises Exchange Servers or installed the tools after removing the Last Exchange Server for recipient management. We recommend applying the Security Update.

Finally, as with any patch or update, test it in a test environment before deploying it to production. However, we do not recommend waiting for regular maintenance cycles for security updates; a more agile approach is preferable, and the ratings indicate the urgency level.

This entry was posted in Exchange Server and tagged , , , , , by Michel de Rooij. Bookmark the permalink.
Unknown's avatar

About Michel de Rooij

Michel de Rooij, with over 25 years of mixed consulting and automation experience with Exchange and related technologies, is a consultant for Rapid Circle. He assists organizations in their journey to and using Microsoft 365, primarily focusing on Exchange and associated technologies and automating processes using PowerShell or Graph. Michel's authorship of several Exchange books and role in the Office 365 for IT Pros author team are a testament to his knowledge. Besides writing for Practical365.com, he maintains a blog on eightwone.com with supporting scripts on GitHub. Michel has been a Microsoft MVP since 2013.

Leave a Reply