Security Updates Exchange 2016-SE (Sep2026)

The Exchange product group released the September 2026 updates for Exchange Server SE, Exchange 2019, and Exchange 2016. The Security Update for Exchange SE is publicly available. Security updates for Exchange 2019 and Exchange 2016 are available to organizations enrolled in the Extended Security Update Period 2 program.

The vulnerabilities addressed in these Security Updates for Exchange Server are:

VulnerabilityCategorySeverityRating
CVE-2026-55007Remote Code ExecutionImportantCVSS:3.1 8.1 / 7.1
CVE-2026-69355Remote Code ExecutionImportantCVSS:3.1 8.8 / 7.7
CVE-2026-69356SpoofingImportantCVSS:3.1 9.3 / 8.1
CVE-2026-69361SpoofingImportantCVSS:3.1 6.5 / 5.7
CVE-2026-69375TamperingImportantCVSS:3.1 6.5 / 5.7
CVE-2026-69378Denial of ServiceImportantCVSS:3.1 7.5 / 6.5
CVE-2026-69380Elevation of PrivilegeImportantCVSS:3.1 8.1 / 7.1
CVE-2026-69382Information DisclosureImportantCVSS:3.1 5.9 / 5.2
CVE-2026-69641Elevation of PrivilegeImportantCVSS:3.1 9.1 / 7.9

Note: CVE-2026-55007 is not addressed in the Exchange Server 2016 SU.

The Security Updates for each supported Exchange Server build are linked below:

ExchangeSU/HUDownloadBuildKBSupersedes
Exchange SE10Download15.2.2562.49KB5121608KB5121573
Exchange 2019 CU1511ESU215.2.1748.51KB5121609KB5121574
Exchange 2019 CU1414ESU215.2.1544.46KB5121610KB5121575
Exchange 2016 CU2325ESU215.1.2507.73KB5121611KB5121576

Fixed Issues

The SU resolves the following issues from previous updates:

Known Issues

Be aware of the following known issue after installing the SU:

Notes

  • Security updates are specific to the Cumulative Update level. You cannot apply the Exchange 2019 CU15 security update to Exchange 2019 CU14. When downloading, the security update might carry the same name for different Cumulative Updates. Microsoft now includes the KB article number as a reference, but I still tag the filename with the CU level for archival purposes, e.g., Exchange2019-CU15-KBxxxxxxx-x64-en.exe.
  • Like Cumulative Updates, Security Updates are cumulative, and you only need to install the latest SU for your CU.
  • Suppose you have deployed Exchange Management Tools to manage your on-premises Exchange Servers or installed the tools after removing the Last Exchange Server for recipient management. We recommend applying the Security Update.

Finally, as with any patch or update, test it in a test environment before deploying it to production. However, we do not recommend waiting for regular maintenance cycles for security updates; a more agile approach is preferable, and the ratings indicate the urgency level.

This entry was posted in Exchange Server and tagged , , , , by Michel de Rooij. Bookmark the permalink.
Unknown's avatar

About Michel de Rooij

Michel de Rooij, with over 25 years of mixed consulting and automation experience with Exchange and related technologies, is a consultant for Rapid Circle. He assists organizations in their journey to and using Microsoft 365, primarily focusing on Exchange and associated technologies and automating processes using PowerShell or Graph. Michel's authorship of several Exchange books and role in the Office 365 for IT Pros author team are a testament to his knowledge. Besides writing for Practical365.com, he maintains a blog on eightwone.com with supporting scripts on GitHub. Michel has been a Microsoft MVP since 2013.

Leave a Reply