CVE-2026-69356 and CVE-2026-69641: Security Updates for Microsoft Exchange Server
This text was generated using artificial intelligence (AI).Microsoft released security updates for two critical vulnerabilities in Exchange Server on September 8, 2026. CVE-2026-69356 is a spoofing vulnerability with a CVSS score of 9.3. CVE-2026-69641 relates to a privilege escalation within Exchange Server and has a CVSS score of 9.1. According to Microsoft's current assessment, neither vulnerability is being actively exploited (as of September 8, 2026).
Certain locally operated Exchange Server installations are affected. Exchange Online is not affected.
Exchange Server 2016 CU23 (ESU Period 2), Exchange Server 2019 CU14 (ESU Period 2), Exchange Server 2019 CU15 (ESU Period 2), Exchange Server Subscription Edition RTM
Microsoft Exchange Server
Exchange Server 2016 CU23 (ESU Period 2), Exchange Server 2019 CU14 (ESU Period 2), Exchange Server 2019 CU15 (ESU Period 2), Exchange Server Subscription Edition RTM
Microsoft Exchange Server
Exchange Server 2016 CU23 (ESU Period 2), Exchange Server 2019 CU14 (ESU Period 2), Exchange Server 2019 CU15 (ESU Period 2), Exchange Server Subscription Edition RTM
Microsoft Exchange Server
Exchange Server 2016 CU23 (ESU Period 2), Exchange Server 2019 CU14 (ESU Period 2), Exchange Server 2019 CU15 (ESU Period 2), Exchange Server Subscription Edition RTM
The security updates affect the following Exchange editions:
Exchange Server 2016 CU23 with ESU Period 2
Exchange Server 2019 CU14 with ESU Period 2
Exchange Server 2019 CU15 with ESU Period 2
Exchange Server Subscription Edition RTM
For Exchange Server 2016 and Exchange Server 2019, the security updates are only available to customers with ESU Period 2 available. Both product lines have been out of regular support since October 14, 2025. ESU Period 2 covers the period from May to October 2026, thus enabling a final phase of paid security updates for organizations that have not yet completed their migration.
CVE-2026-69356: Sender Identity Spoofing
CVE-2026-69356 is designated as Microsoft Exchange Server Spoofing Vulnerability. According to Microsoft MSRC, an attacker can spoof another sender in the process. The attack is network-based, requires no elevated privileges, and requires user interaction.
The vulnerability has a CVSS score of 9.3.
CVE-2026-69641: Privilege Escalation in Exchange Server
CVE-2026-69641 is classified as Microsoft Exchange Server Elevation of Privilege Vulnerability classified. The vulnerability allows privilege escalation within Exchange Server and requires high privileges from the attacker, but no user interaction. Microsoft MSRC assigns the vulnerability a CVSS score of 9.1 out. The CVSS attribute Scope Changed indicates that a successful attack can have an impact beyond the Exchange server.
Check patch status, ESU eligibility and migration
Organizations with locally operated Exchange Servers should first check whether the mentioned Exchange editions are in use and whether CVE-2026-69356 or CVE-2026-69641 are relevant. For Exchange Server 2016 and 2019, this also includes checking ESU Period 2 eligibility.
Microsoft recommends installing the September 2026 security update on all affected Exchange servers. To verify a successful installation, the Exchange team recommends the Exchange Server Health Checker, according to the Microsoft Exchange Team Blog.
Without ESU Period 2, the migration to Exchange Server Subscription Edition should be prioritized. The migration is also relevant for environments with ESU Period 2, as this update phase only runs until October 2026.
According to Microsoft, no action is required from this advisory for Exchange Online.
Organisations in Germany and Austria that fall under the NIS-2 Directive – implemented in Germany via the NIS2UmsuCG, in Austria via the NISG – are required to evaluate and apply critical security updates without delay. The BSI generally recommends installing critical patches within a few days of release. In Switzerland, the revised Information Security Act (ISG) applies; operators of critical infrastructures are subject to a reporting obligation to the BACS in the event of exploitable vulnerabilities in critical systems.
Map externally accessible Exchange services
On-premises Exchange servers can be publicly accessible under their own domain. LocateRisk can make such externally accessible mail servers visible as assets and prioritize them for technical processing.
This visibility does not replace an inspection of installed software versions and no verification of actual impact by CVE-2026-69356 or CVE-2026-69641. For processing, therefore, the assignment of the detected service to owners and operating model, the verification of ESU Period 2 eligibility, and the control of the patch status belong together.
In Vendor Risk Management, LocateRisk can incorporate security notifications regarding technology providers into the assessment of external dependencies. In the case of this notification, the direct technical reference lies with one's own publicly accessible Exchange instances.
Am I affected?
Microsoft Exchange Server in the versions mentioned above is affected. Anyone who wants to know whether Microsoft Exchange Server is even visible in their own externally accessible infrastructure can use the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed from the outside—the key factor is comparing it with the manufacturer's advisory.
Affected are Exchange Server 2016 CU23 (ESU Period 2), Exchange Server 2019 CU14 (ESU Period 2), Exchange Server 2019 CU15 (ESU Period 2), as well as Exchange Server Subscription Edition RTM. Exchange Online is not affected.
According to Microsoft's current assessment, neither vulnerability is being actively exploited. However, Microsoft classifies the exploitability as critical, which is why installing the September 2026 security update is recommended.
ESU Period 2 is a paid program that provides security updates for Exchange Server 2016 and 2019 beyond their regular end of support (October 14, 2025). The period runs from May 2026 to October 2026. Enrollment is not automatic; organizations must purchase ESU Period 2 separately.
The CVSS attribute Scope Changed means that a successful attack can have an impact beyond the affected component—the Exchange server itself—and potentially affect adjacent systems or resources.
As of September 9, 2026. This post is for general informational purposes and does not constitute legal, security, or operational advice in individual cases. The security situation and patch availability may have changed since publication; the linked manufacturer advisory is always authoritative. Despite careful research, we assume no liability for timeliness, accuracy, and completeness.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2026-69356
Passive Assessment
Information About the CVEfound or not found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.