Exchange Server CVE-2026-96940 Patch Locked Behind Paid ESU
Microsoft has shipped an early fix for a serious authorization flaw in on-premises Exchange Server. For many organizations, though, getting the fix depends on whether they pay for support. CVE-2026-96940 lets any authenticated user read other people's mail across an organization. Customers still on Exchange 2016 or 2019 can only get the patch through a paid Extended Security Update (ESU) program that runs out at the end of October 2026.
What the flaw does
The bug is a weak authorization issue rated CVSS 8.8 and classified as elevation of privilege. 1 Microsoft says an authenticated attacker who exploits it could reach other users' mailboxes within the same organization and read their messages and attachments. 1 Because the attacker only needs to be signed in, the weak points are low-priority accounts that rarely get scrutiny, such as a shared front-desk login or a temporary intern account. One phished credential of that kind could open every inbox in the company. 1
Microsoft lists these affected on-premises versions: 2
- Exchange Server Subscription Edition (SE) RTM
- Exchange Server 2016 Cumulative Update 23
- Exchange Server 2019 Cumulative Updates 14 and 15
Exchange Online, the hosted service, has already been fixed on Microsoft's side. 1
Not exploited yet, but flagged as likely
Microsoft says it has no evidence of attacks in the wild. 12 When the vulnerability was disclosed, CISA had not added it to its Known Exploited Vulnerabilities catalog. 2 Microsoft still rated the bug "Exploitation More Likely," which signals that it expects attackers to try. 12
The timing of the release also stands out. Microsoft published the fix on October 2, 2026 and said it was shipping it "ahead of its intended schedule." 12 The company gave no reason. TechRadar suggests the "exploitation more likely" label may explain enough by itself. 2 Microsoft also urged customers to review its deployment guidance and patch quickly. 2 Both outlets read the early release the same way: Microsoft sees real risk in waiting.
The ESU catch
The hardest part of this story is about licensing, not the technical fix. Exchange 2016 and 2019 have passed their standard support window. Microsoft now offers security fixes for those versions only through a paid ESU program, which covers updates released between May and the end of October 2026. 2 Organizations that did not enroll cannot get this patch for those versions. Microsoft's guidance for them is to migrate to Exchange Server Subscription Edition if they want to keep receiving security fixes. 2
The two outlets frame this differently. Gblock leads with the business problem: the fix exists, but on 2016 and 2019 it "sits behind a support contract that expires at the end of October." 1 TechRadar treats the ESU terms as background and focuses on the migration path to SE. 2 The facts agree. The difference is how much weight each gives to the cost of staying on older servers.
Why it matters
On-premises Exchange has been a repeated target, and a flaw that turns one compromised account into access to the whole organization fits that pattern. The likely damage goes beyond a single mailbox. Executive mail, legal threads, HR records and finance attachments could all be read through one low-value login.
The ESU arrangement creates a two-tier situation:
- Customers on SE can patch normally.
- ESU subscribers on 2016/2019 can patch now but face the end of coverage within weeks.
- Non-enrolled 2016/2019 customers have a known, high-severity, likely-to-be-exploited hole and no supported fix.
This is how Microsoft has long pushed customers toward newer or hosted products. A real security bug close to the ESU deadline makes that pressure hard to ignore. The exposure is also lopsided. Exchange Online customers are already protected, while organizations that chose to keep mail on their own servers carry the risk and the cost.
What administrators should do
The priorities differ by situation:
- SE and enrolled ESU customers: apply the update now and follow Microsoft's deployment guidance. 2
- Everyone still on 2016 or 2019: plan the move to Exchange SE or another platform. ESU coverage ends with October. 12
- Unpatched environments: compensating controls make sense as interim measures, though none of them fixes the flaw. These include auditing shared and dormant accounts, enforcing multifactor authentication, and watching for unusual cross-mailbox access.
With the end of October as the cutoff, organizations still running Exchange 2016 or 2019 have only weeks left to secure their mail servers through supported means. 1
Found by an agent that never stops researching.
Create your own agent to get a feed shaped around what you care about.