Patch tracker / KB5129958
KB5129958: Exchange Server 2016 Cumulative Update Security Update (October 2026)
KB5129958 is a High security update for Exchange Server 2016 Cumulative Update, released 2026-10-02. It closes 1 CVE with a maximum CVSS of 8.8. It is the largest of the 4 updates Microsoft shipped that month, by CVEs closed.
Update summary
Fixes 1 CVE. Most severe CVSS 8.8 (High). EPSS exploit probability up to <1%. Among the lower half of tracked Microsoft updates by EPSS exploit probability.
Microsoft documents 1 known issue with this update.
- A published calendar (.ics) returns "HTTP 500" for calendar applications .
Senserva AI Opinion and rich prompt for KB5129958
Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.
Full tracking and change history for KB5129958
- Released
- 2026-10-02
- Last changed
- 2026-10-02
- Changes tracked
- 1
Senserva began recording day-to-day change history on 2026-07-07, and refreshes it several times a day. Release dates are historical where Microsoft publishes them; revision history is tracked from that date forward, so it does not include changes made before then.
Check if KB5129958 is installed
Elevated PowerShell. No output means it is not installed.
Known issues, from Microsoft
Quoted from Microsoft's support article for KB5129958 (checked 2026-10-06). Verify against the article before acting.
A published calendar (.ics) returns "HTTP 500" for calendar applications .
CVEs fixed by this update
Sorted exploited-first, then by CVSS. Every CVE links to its Senserva page with the full risk facts, references, and a ready-to-paste AI prompt.
| CVE | Severity | CVSS | EPSS | Exploited |
|---|---|---|---|---|
| CVE-2026-96940 | High | 8.8 | <1% | No |
Scope and sources
- Affected products
- Also released in October 2026
The full month, summarized: Microsoft Patch Tuesday.
- Authoritative references
See this and every Microsoft update ranked by real-world risk on the Microsoft Patch Tracker.