Microsoft announced V2 September 2026 security updates for Exchange Server Subscription Edition, Exchange Server 2019, and Exchange Server 2016 on October 2. NVD lists CVE-2026-96940 as affecting specified builds in four Exchange branches, but the available announcement details do not establish the V2 package identifiers or the complete change from V1. Administrators should check their branch and installed build against current Microsoft guidance before deciding which update to install.
What changed with the September 2026 V2 updates?
The Microsoft Exchange Team announced the V2 release on October 2, 2026, for Exchange Server Subscription Edition, Exchange Server 2019, and Exchange Server 2016. The announcement details available here do not identify the exact V2 package revisions or explain the complete reason for reissuing the updates. Do not assume that V2 simply adds CVE-2026-96940, or use a V1 package identifier as a V2 identifier.
NVD published its record for CVE-2026-96940 on October 2, 2026, and last modified it on October 3. NVD classifies the weakness as CWE-1390, Weak Authentication. That classification and the affected-version list below do not, by themselves, establish a specific attack scenario or severity.
Which Exchange builds does NVD list as affected?
NVD lists versions below these branch-specific thresholds as affected. Match the threshold to the installed product and cumulative update (CU); the numbers are not interchangeable across branches.
#1 Best Overall
| Exchange branch | NVD-listed affected versions | Threshold |
|---|---|---|
| Exchange Server 2016 CU23 | Builds below | 15.01.2507.075 |
| Exchange Server 2019 CU14 | Builds below | 15.02.1544.048 |
| Exchange Server 2019 CU15 | Builds below | 15.02.1748.053 |
| Exchange Server Subscription Edition RTM | Builds below | 15.02.2562.053 |
Source for the affected branches and thresholds: NVD’s CVE-2026-96940 record. A build at or above its listed threshold is not included in NVD’s stated affected range for that branch; administrators should still use Microsoft’s current update guidance to verify the required security update and installation state.
How should administrators identify and install the right update?
- Identify the Exchange branch and CU. Confirm whether the server is Exchange Subscription Edition RTM, Exchange 2019 CU14 or CU15, or Exchange 2016 CU23 before comparing its build with NVD’s threshold.
- Check Microsoft’s current update guidance for that branch. The available V2 announcement does not provide verified package identifiers for each branch. Do not infer the V2 KB number from the September 8 V1 pages.
- Install the applicable Microsoft security update using the instructions for that package. Follow Microsoft’s current guidance for prerequisites, installation, and any required post-installation actions; the available announcement details do not establish those package-specific instructions.
- Verify installation with Exchange Server Health Checker. Microsoft directs administrators to use Health Checker to verify the September update installation and determine whether further action is needed.
Which September package details are confirmed—and which are not?
Microsoft’s September 8 V1 pages identify these packages. They are useful for distinguishing the earlier release from the October 2 reissue, but they do not establish the V2 package identifiers or whether known issues changed in V2.
| Product and release | September 8 V1 package identified by Microsoft | What the V1 page says |
|---|---|---|
| Exchange Server Subscription Edition RTM, SU10 | KB5121608 | Lists eight CVEs, three known issues, and two resolved issues. |
| Exchange Server 2019 CU15, SU11 | KB5121609 | Lists eight CVEs and a known issue involving published calendars returning HTTP 500. |
The Subscription Edition V1 page’s three known issues were published calendar .ics responses returning HTTP 500, delegated mailbox free/busy failures in hybrid deployments using Graph API only, and a ContentEngine deadlock related to missing Korean WordBreaker rule files. Those are V1 page details, not a confirmed V2 issue list. The Exchange 2019 CU15 V1 page also identifies the published-calendar HTTP 500 issue; it does not establish whether V2 changes that behavior.
What does the reissue mean for Exchange 2016 and 2019 support?
Microsoft’s September 8 Exchange 2019 update page says Exchange Server 2016 and 2019 have reached end of support. It also says organizations enrolled in Period 2 Extended Security Updates (ESU) are eligible for released security updates through the end of October 2026. Organizations not enrolled in ESU are directed to migrate to Exchange Server Subscription Edition to continue receiving the latest security updates. The page provides a Microsoft contact address for ESU access inquiries.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Rank #3
For an Exchange 2016 or 2019 deployment, check ESU enrollment as well as the server’s build. The October deadline is close as of October 3, 2026; if the organization is not enrolled, plan the migration path rather than assuming it will continue to receive security updates after support has ended.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Can Exchange Emergency Mitigation Service replace the security update?
No. Microsoft describes Exchange Emergency Mitigation Service as optional and says it can apply temporary mitigations for known threats. Its mitigations are interim measures until the applicable Security Update is installed; they are not a replacement for installing an Exchange SU. Microsoft’s EM Service documentation describes checking mitigation status with Exchange PowerShell and provides a Get-Mitigations.ps1 script. The available documentation does not confirm a CVE-2026-96940-specific mitigation, so do not assume one is available.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

