Security Updates Exchange 2016-2019 & SE (Dec2025)


The Exchange product group released the December 2025 Security Update for Exchange Server SE. Organizations that enrolled in the Extended Security Update program will also have access to December 2025 security updates for Exchange Server 2019 and Exchange Server 2016. These ESU updates will not be made available publicly.

The vulnerabilities addressed in these Security Updates for Exchange Server are:

VulnerabilityCategorySeverityRating
CVE-2025-64666Elevation of PrivilegeImportantCVSS:3.1 7.5 / 6.5
CVE-2025-64667SpoofingImportantCVSS:3.1 5.3 / 4.6

The Security Updates for each supported Exchange Server build are linked below:

ExchangeSU/HUDownloadBuildKBSupersedes
Exchange SE4Download15.2.2562.29KB5071876KB5066366
Exchange 2019 CU156ESU Program15.2.1748.42KB5071875KB5066367
Exchange 2019 CU149ESU Program15.2.1544.37KB5071874KB5066368
Exchange 2016 CU2320ESU Program15.1.2507.63KB5071873KB5066369

Fixed Issues

The issue addressed in these hotfixes is:

Notes

  • Security updates are Cumulative Update level specific. You cannot apply the Exchange 2019 CU15 update to Exchange 2019 CU14. When downloading, the security update might carry the same name for different Cumulative Updates. Nowadays, Microsoft adds the KB article number as a reference, but I would still tag the file name with the CU level for archival purposes, e.g., Exchange2019-CU15-KBxxxxxxx-x64-en.exe.
  • Like Cumulative Updates, Security Updates are cumulative, and you only need to install the latest SU for your CU.
  • Suppose you have deployed Exchange Management Tools to manage your on-premises Exchange Servers or installed the tools after removing the Last Exchange Server for recipient management. In that case, it is recommended that you apply the Security Update.

On a final note, as with any patch or update, it is recommended that you apply it in a test environment before implementing it in production. However, it is not recommended to wait for regular maintenance cycles when it comes to security updates; a more agile approach is preferable, and the ratings indicate the level of urgency.

Security Updates Exchange 2016-2019 & SE (Oct2025)


The Exchange product group released the October 2025 Security Updates for Exchange Server SE, Exchange Server 2019, and Exchange Server 2016.

The vulnerabilities addressed in these Security Updates for Exchange Server are:

VulnerabilityCategorySeverityRating
​​​​​​​​​​​​​​CVE-2025-59249Elevation of PrivilegeImportantCVSS:3.1 8.8 / 7.7
CVE-2025-53782Elevation of PrivilegeImportantCVSS:3.1 8.4 / 7.3
CVE-2025-59248SpoofingImportantCVSS:3.1 7.5 / 6.5

The Security Updates for each supported Exchange Server build are linked below:

ExchangeSU/HUDownloadBuildKBSupersedes
Exchange SE3Download15.2.2562.29KB5066366KB5063224
Exchange 2019 CU155Download15.2.1748.39KB5066367KB5063221
Exchange 2019 CU148Download15.2.1544.36KB5066368KB5063222
Exchange 2016 CU2319Download15.1.2507.61KB5066369KB5063223

Last SU for Exchange 2019 and Exchange 2016

These Security Updates are the SUs for Exchange Server 2016 and 2019 that will be publicly available. Any Extended Security Updates (ESU) that might be released between now and April 2026 for these products need to be acquired by contacting your Microsoft Account Teams.

Auth Certificate Export

Be advised that after deploying the October SU, as a security measure, Export-ExchangeCertificate can no longer be used to export of the Auth Certificate. For more information, see KB5069337.

Notes

  • Security updates are Cumulative Update level specific. You cannot apply the update for Exchange 2019 CU15 to Exchange 2019 CU14. When downloading, the security update might carry the same name for different Cumulative Updates. Nowadays, Microsoft adds the KB article number as a reference, but I would still tag the file name with the CU level for archival purposes, e.g., Exchange2019-CU15-KB5063221-x64-en.exe.
  • Like Cumulative Updates, Security Updates are cumulative, and you only need to install the latest SU for your CU.
  • Suppose you have deployed Exchange Management Tools to manage your on-premises Exchange Servers or installed the tools after removing the Last Exchange Server for recipient management. In that case, it is recommended that you apply the Security Update.

On a final note, as with any patch or update, it is recommended that you apply it in a test environment before implementing it in production. However, it is not recommended to wait for regular maintenance cycles when it comes to security updates and follow a more agile approach; the ratings indicate the level of urgency.

Hotfix Updates Exchange 2016-SE (Sep2025)


The Exchange product group released the September 2025 Hotfix Updates for Exchange Server SE, Exchange Server 2019, and Exchange Server 2016.

Hotfix updates do not contain security fixes, but address issues. They also might introduce or add support for functionality changes, such as dedicated Exchange hybrid app support.

ExchangeSU/HUDownloadBuildKBSupersedes
Exchange SE2Download15.2.2562.27KB5066373
Exchange 2019 CU154Download15.2.1748.37KB5066372KB5057651
Exchange 2019 CU147Download15.2.1544.34KB5066371KB5057652
Exchange 2016 CU2318Download15.1.2507.59KB5066370KB5057653

Changes

The issue addressed in these hotfixes is:

Dedicated Exchange Hybrid Application

A gentle reminder that since the April 2025 security updates, Exchange hybrid supports the dedicated Exchange hybrid app. The dedicated Exchange hybrid app becomes mandatory in October 2025 for continued cross-premises functionality (free/busy, etc.). To make the required changes related to the Graph permissions model, you have some more time, as that will become required in October 2026. For more information, please visit this link.

Do note that Microsoft scheduled some planned disruptions.This is likely in an attempt to nudge those Exchange hybrid customers who have not yet implemented the new dedicated hybrid app. So, if you are running Exchange hybrid with mailboxes on-premises and in Exchange Online, have not deployed the April 2025 SU or later, or did not implement the dedicated Exchange hybrid app, here are some time windows to keep an eye on:

  • Sep16-18 (7am-7am). Affected regions: WW, GCC, GCC-H, DoD, 21Vianet
  • Oct7-9 (7am-7am).

Symptoms: Users with mailboxes on-premises might not be able to see free/busy, MailTips or profile pictures from users with a mailbox in Exchange Online. Only EWS functionality is affected, thus things such as migration jobs and mail flow keep functioning.

For more information, keep an eye on the EHLO blog announcements.

Security Updates Exchange 2016-2019 & SE (Aug2025)


The Exchange product group released the August 2025 Hotfix Updates for Exchange Server SE, Exchange Server 2019, and Exchange Server 2016. The SU for SE comes barely a month after the RTM release of Exchange SE RTM.

The vulnerabilities addressed in these Security Updates for Exchange Server are:

VulnerabilityCategorySeverityRating
CVE-2025-25005TamperingImportantCVSS:3.1 6.5 / 5.7
CVE-2025-25006SpoofingImportantCVSS:3.1 5.3 / 4.6
CVE-2025-25007SpoofingImportantCVSS:3.1 5.3 / 4.6
CVE-2025-33051Information DisclosureImportantCVSS:3.1 7.5 / 6.5

The Security Updates for each supported Exchange Server build are linked below:

ExchangeSUDownloadBuildKBSupersedes
Exchange SE1Download15.2.2562.20KB5063224
Exchange 2019 CU153Download15.2.1748.36KB5063221KB5049233
Exchange 2019 CU146Download15.2.1544.33KB5063222KB5049233
Exchange 2016 CU2317Download15.1.2507.58KB5063223KB5049233

Feature Changes

The November SUs for Exchange 2019 and Exchange 2016 introduced AMSI integration. AMSI was disabled by default after deploying this SU. Now, with the August 2025 SUs, AMSI body scanning will be enabled for all protocols. Consult the documentation on how to disable AMSI scanning should you encounter any issues.

Fixed Issues

Apart from security fixes and added features, these Security Updates also correct the following issues:

Issue Fixed
Exchange Server fails to export eDiscovery search results to a discovery mailbox
Application pools stop responding and performance is affected after MSIPC is enabled
Incorrect ACE is modified through public folder management in Outlook​​​​​​​​​​​​​​

Notes

  • Security updates are Cumulative Update level specific. You cannot apply the update for Exchange 2019 CU15 to Exchange 2019 CU14. When downloading, the security update might carry the same name for different Cumulative Updates. Nowadays, Microsoft adds the KB article number as reference, but I would still tag the file name with the CU level for archival purposes, e.g., Exchange2019-CU15-KB5063221-x64-en.exe.
  • Like Cumulative Updates, Security Updates are cumulative, and you only need to install the latest SU for your CU.
  • Suppose you have deployed Exchange Management Tools to manage your on-premises Exchange Servers or installed the tools after removing the Last Exchange Server for recipient management. In that case, it is recommended that you apply the Security Update.

On a final note, as with any patch or update, it is recommended that you apply it in a test environment before implementing it in production. However, it is not recommended to wait for regular maintenance cycles when it comes to security updates and follow a more agile approach; the ratings indicate the level of urgency.

MVPs around the World (2025)


31Jul: Moved MVPs per country to bottom and expanded table.

Another year, another Microsoft MVP award cycle. Always a great moment to have a quick peek at the MVP population. Note that this year, this post took a while longer to get published. This is due to the date of awards being announced, as well as the vacation period, which caused delays in people confirming their renewal agreement.

The numbers below are taken from the public MVP portal on July 30th. Comparing them to July from recent years should give an idea of trends and what award categories (and thus products) have focus.

A few notes:

  • 3.589 public MVP profiles were processed. The overall number went up compared to last year. However, compared to the MVPs of June, the overall number went down by 12%.
  • The award category Mixed Reality has been closed. Have a look at the Sankey diagram further down this article to see where these people went.
  • The number of countries represented went down when compared to last year.
  • The number of MVPs with more than one award category has increased by 13%.
  • The MVP award category with the most MVPs is still the Developer Technologies.

MVP Awardees per Category

The following chart and table display the awardees per award category from 2021 to 2025, plus change percentages compared to previous years.

Award CategoryJul2021Jul2022%Jul2023%Jul2024%Jul2025%
AI Platform138128-7%105-18%269156%38643%
Business Applications3233519%44226%4747%4832%
Cloud and Datacenter Management219164-25%136-17%111-18%106-5%
Data Platform392364-7%335-8%307-8%3297%
Developer Technologies770715-7%7474%7612%85913%
Enterprise Mobility13314912%100-33%0-100%00%
Internet of Things000%430%430%39-9%
M365556492-12%54110%64319%81927%
M365 Development6959-14%7019%0-100%00%
Microsoft Azure5345462%526-4%5270%5392%
Mixed Reality000%450%35-22%0-100%
Security000%1710%30578%34914%
Windows and Devices42457%6136%10267%13330%
Windows Development12092-23%37-60%30-19%3517%
Total Categories32963105-6%33598%36077%407713%
Total MVPs32233023-6%31755%31870%358913%

Note: The difference between total categories and total MVPs is caused by MVPs that are awarded in more than one category.

Where did they go?

The Sankey diagram below displays the number of awarded categories moving from last year to now. The move is based on the MVP, the categories they had, and the new categories they have currently been awarded in. New awardees are categorized as “New,” and those who are no longer present on the MVP portal (e.g., no longer MVP) are categorized as “Out.”

MVP Awardees per Country

The following chart and table display the awardees per country, plus change percentages compared to July last year. Countries that show a 0 no longer have any published MVPs. This used to be a condensed table, but I have expanded the table and added fun facts such as MVPs per population and area as well, using apicountries.com as a reference.

CountryWasNowChangeMVPs per
1,000,000
MVPs per
1,000 km2
Albania110%             0,35         0,035
Angola110%             0,03         0,001
Argentina171912%             0,42         0,007
Australia1111132%             4,40         0,015
Austria323716%             4,15         0,441
Azerbaijan43-25%             0,30         0,035
Bahrain12100%             1,18         2,614
Bangladesh31-67%             0,01         0,007
Belgium59648%             5,54         2,096
Benin01100%             0,08         0,009
Bolivia54-20%             0,34         0,004
Bosnia and Herzegovina76-14%             1,83         0,117
Brazil1271367%             0,64         0,016
Bulgaria880%             1,15         0,072
Cambodia01100%             0,06         0,006
Cameroon13200%             0,11         0,006
Canada11513013%             3,42         0,013
Chile4525%             0,26         0,007
China137132-4%             0,09         0,014
Colombia1614-13%             0,28         0,012
Congo (DRC)41-75%             0,01         0,000
Costa Rica220%             0,39         0,039
Côte d’Ivoire110%             0,04         0,003
Croatia1311-15%             2,72         0,194
Czechia263119%             2,90         0,393
Denmark496022%           10,29         1,392
Dominican Republic36100%             0,55         0,123
Ecuador440%             0,23         0,014
Egypt81025%             0,10         0,010
El Salvador220%             0,31         0,095
Estonia440%             3,01         0,088
Finland333918%             7,05         0,115
France120113-6%             1,68         0,176
Gabon01100%             0,45         0,004
Georgia12100%             0,54         0,029
Germany14317724%             2,13         0,496
Ghana660%             0,19         0,025
Greece1110-9%             0,93         0,076
Guatemala13200%             0,18         0,028
Honduras110%             0,10         0,009
Hong Kong SAR6717%             0,94         6,341
Hungary86-25%             0,62         0,064
Iceland5620%           16,37         0,058
India11814725%             0,11         0,045
Indonesia7929%             0,03         0,005
Ireland3231-3%             6,21         0,441
Israel121742%             1,84         0,818
Italy69759%             1,26         0,249
Japan1511649%             1,30         0,434
Jordan110%             0,10         0,011
Kazakhstan01100%             0,05         0,000
Kenya7814%             0,15         0,014
Korea56584%             1,12         0,579
Latvia13200%             1,58         0,046
Lebanon110%             0,15         0,096
Lithuania65-17%             1,79         0,077
Luxembourg12100%             3,16         0,773
Malaysia75-29%             0,15         0,015
Malta13200%             5,71         9,494
Mauritius12100%             1,58         0,980
Mexico182117%             0,16         0,011
Morocco4775%             0,19         0,016
Myanmar110%             0,02         0,001
Nepal4525%             0,17         0,034
Netherlands17519511%           11,18         4,659
New Zealand32359%             6,88         0,129
Nicaragua32-33%             0,30         0,015
Nigeria2623-12%             0,11         0,025
North Macedonia5860%             3,84         0,311
Norway405025%             9,29         0,154
Oman01100%             0,20         0,003
Pakistan91567%             0,07         0,017
Panama31-67%             0,23         0,013
Paraguay110%             0,14         0,002
Peru131515%             0,45         0,012
Philippines660%             0,05         0,018
Poland667311%             1,92         0,233
Portugal23259%             2,43         0,271
Puerto Rico110%             0,31         0,113
Qatar01100%             0,35         0,086
Réunion10-100%                –   –
Romania121958%             0,99         0,080
Saudi Arabia440%             0,11         0,002
Senegal10-100%                –                 –  
Serbia71043%             1,45         0,113
Singapore202315%             4,05       32,394
Slovakia4525%             0,92         0,102
Slovenia770%             3,33         0,345
South Africa111427%             0,24         0,011
Spain10312218%             2,58         0,241
Sri Lanka10100%             0,46         0,152
Sweden809620%             9,27         0,213
Switzerland536319%             7,29         1,526
Taiwan45462%             1,96         1,271
Tanzania110%             0,02         0,001
Thailand16176%             0,24         0,033
Tunisia10-100%                –                 –  
Türkiye202420%             0,28         0,031
Ukraine141614%             0,36         0,027
United Arab Emirates3433%             0,40         0,048
United Kingdom27330411%             4,52         1,252
United States48955814%             1,69         0,058
Uruguay220%             0,58         0,011
Uzbekistan21-50%             0,03         0,002
Venezuela110%             0,04         0,001
Vietnam550%             0,05         0,015
Yemen110%             0,03         0,002

If you have questions or comments, please leave them in the comments below.