Exchange admins need September V2 patches for new privilege flaw
Microsoft’s September V2 Exchange Server updates add a fix for CVE-2026-96940, a network-accessible privilege-escalation flaw that can expose other users’ mailboxes. The update builds on September’s Exchange fixes for remote-code execution and mailbox-takeover risks ; on-premises administrators should verify they have the V2 patches installed. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
