DEV Community

kozhevniko
kozhevniko

Posted on

Known issues to expect when you install the Exchange V2 security update

Known issues to expect when you install the Exchange V2 security update

What changed in V2

Microsoft shipped a V2 release of its September 2026 Exchange Server security updates. The only change against the original release is the addition of CVE-2026-96940. The Exchange Team states it identified the vulnerability internally and is not aware of active exploitation.

Known issue: published calendar links

Published calendar (.ics) links return an HTTP 500 error after this update. Microsoft plans to address the problem in a future release, so calendar publishing needs a workaround or a deferred deployment where it is business critical.

Known issue: ContentEngine deadlock

A ContentEngine deadlock affects mailboxes with Korean-language email. The same caveat applies: the fix is scheduled for a later update rather than the current package.

Hybrid problems the update resolves

The update resolves two hybrid problems: wrapper messages no longer appear in shared mailbox inboxes, and free/busy lookups now work for delegated mailboxes in Graph-only hybrid setups.

Planning around the issues

Both known issues are documented behaviour rather than reasons to skip the update. Record which mailbox sets and calendar publishers are affected, schedule the change window around them, and keep a rollback plan for the hybrid services this package touches.

Affected builds

The V2 updates cover Exchange Server Subscription Edition (SE) RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23. Exchange 2016 and Exchange 2019 have left mainstream support, so only organisations enrolled in the Period 2 Extended Security Update (ESU) programme, which covers updates released between May and October 2026, can download those fixes.

References

Reported by SecurityOnline.info, which summarises the Exchange Team announcement of the September 2026 V2 security updates.

Top comments (0)