The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Microsoft published version 2 of its September 2026 security updates for on-premises Exchange on October 2, 2026. Install the package that matches your server’s edition and cumulative update (CU): V2 includes CVE-2026-96940, and the packages are not interchangeable. Exchange 2016 and 2019 administrators also need to confirm Period 2 Extended Security Updates (ESU) eligibility; Microsoft says those versions have reached end of support.
Which V2 Exchange update matches your server?
Use the package for the exact Exchange track and CU installed. Microsoft identifies KB5129955 as version 2 for Exchange Server Subscription Edition (SE) RTM. The package mappings and builds below are reported in the specialist release roundup; Microsoft’s KB pages also confirm the SE and Exchange 2019 CU15 package identities.
| Exchange track | V2 package | Build | Availability |
|---|---|---|---|
| Exchange Server Subscription Edition RTM | KB5129955 | 15.2.2562.53 | Public download; see Microsoft’s KB5129955 and the release roundup. |
| Exchange 2019 CU15 | KB5129956 | 15.2.1748.53 | Period 2 ESU participants; see Microsoft’s KB5129956. |
| Exchange 2019 CU14 | KB5129957 | 15.2.1544.48 | Period 2 ESU participants, according to the release roundup. |
| Exchange 2016 CU23 | KB5129958 | 15.1.2507.75 | Period 2 ESU participants, according to the release roundup. |
CU matching matters: a security update for Exchange 2019 CU15 cannot be applied to CU14. Microsoft’s Exchange update guidance likewise says security updates are CU-specific. If you move to a newer CU, apply the latest security update for that CU.
What changed in V2, and what is known about the flaw?
Microsoft’s KB5129955 names CVE-2026-96940 among the vulnerabilities addressed. The specialist release roundup characterizes it as an Important elevation-of-privilege issue and says it is an additional fix over the original September updates. Microsoft’s accessible KB content does not establish detailed attack prerequisites, whether exploitation is remote or requires authentication, or whether the flaw is being exploited in the wild; those details should not be inferred from the severity label.
#1 Best Overall
The V2 release is not an instruction to install both September versions. Microsoft’s general servicing guidance says a newer security update for a CU includes earlier security updates for that same CU, so administrators who skipped the original September update can install the applicable V2 package rather than installing each intervening update separately. Check the relevant KB for its package-specific notes.
Are Exchange 2016 and 2019 still receiving security updates?
Microsoft says Exchange 2016 and Exchange 2019 have reached end of support. Organizations enrolled in Period 2 ESU can receive released security updates until the end of October 2026. Microsoft directs organizations that are not enrolled in ESU to migrate to Exchange Server Subscription Edition to continue receiving security updates. The Exchange 2016 and 2019 V2 packages in the table are therefore for eligible ESU participants, not a general extension of support.
Rank #2
How to deploy the matching update and verify it
- Inventory the server. Record its Exchange edition and exact CU, then check whether Exchange 2016 or 2019 is covered by Period 2 ESU.
- Choose the matching package. Use the table and open the corresponding Microsoft KB or official update route. Do not substitute a package intended for another CU.
- Follow the Microsoft deployment instructions and your change process. Microsoft recommends keeping on-premises Exchange current and being prepared to deploy emergency security updates. Its guidance also recommends installing security updates on Exchange servers and on servers or workstations running Exchange Management Tools, to avoid incompatibility between management-tool clients and servers.
- Run Exchange Server Health Checker after installation. Microsoft recommends the Exchange Server Health Checker to confirm the update and identify any remaining steps. Review the KB for the exact package you installed for known issues that may affect your environment.
Known issues to check in the relevant KB
The notices differ by Exchange track, so check the KB for the package installed rather than assuming every listed issue affects every edition.
Quick Recap
Rank #4
- Exchange Server Subscription Edition KB5129955: Microsoft lists published calendars (.ics) returning HTTP 500 errors in calendar applications; delegated-mailbox free/busy availability failing in certain hybrid deployments that use Graph API only; and a ContentEngine deadlock associated with missing Korean WordBreaker rule files.
- Exchange 2019 CU15 KB5129956: Microsoft lists the published-calendar HTTP 500 issue. Its KB also describes a resolved shared-mailbox wrapper-message issue.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




