Known issues to expect when you install the Exchange V2 security update
What changed in V2
Microsoft shipped a V2 release of its September 2026 Exchange Server security updates. The only change against the original release is the addition of CVE-2026-96940. The Exchange Team states it identified the vulnerability internally and is not aware of active exploitation.
Known issue: published calendar links
Published calendar (.ics) links return an HTTP 500 error after this update. Microsoft plans to address the problem in a future release, so calendar publishing needs a workaround or a deferred deployment where it is business critical.
Known issue: ContentEngine deadlock
A ContentEngine deadlock affects mailboxes with Korean-language email. The same caveat applies: the fix is scheduled for a later update rather than the current package.
Hybrid problems the update resolves
The update resolves two hybrid problems: wrapper messages no longer appear in shared mailbox inboxes, and free/busy lookups now work for delegated mailboxes in Graph-only hybrid setups.
Planning around the issues
Both known issues are documented behaviour rather than reasons to skip the update. Record which mailbox sets and calendar publishers are affected, schedule the change window around them, and keep a rollback plan for the hybrid services this package touches.
Affected builds
The V2 updates cover Exchange Server Subscription Edition (SE) RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23. Exchange 2016 and Exchange 2019 have left mainstream support, so only organisations enrolled in the Period 2 Extended Security Update (ESU) programme, which covers updates released between May and October 2026, can download those fixes.
References
Reported by SecurityOnline.info, which summarises the Exchange Team announcement of the September 2026 V2 security updates.
Top comments (0)