Security Updates Exchange 2016-SE (Sep2026)

The Exchange product group released the September 2026 updates for Exchange Server SE, Exchange 2019, and Exchange 2016. The Security Update for Exchange SE is publicly available. Security updates for Exchange 2019 and Exchange 2016 are available to organizations enrolled in the Extended Security Update Period 2 program.

The vulnerabilities addressed in these Security Updates for Exchange Server are:

VulnerabilityCategorySeverityRating
CVE-2026-55007Remote Code ExecutionImportantCVSS:3.1 8.1 / 7.1
CVE-2026-69355Remote Code ExecutionImportantCVSS:3.1 8.8 / 7.7
CVE-2026-69356SpoofingImportantCVSS:3.1 9.3 / 8.1
CVE-2026-69361SpoofingImportantCVSS:3.1 6.5 / 5.7
CVE-2026-69375TamperingImportantCVSS:3.1 6.5 / 5.7
CVE-2026-69378Denial of ServiceImportantCVSS:3.1 7.5 / 6.5
CVE-2026-69380Elevation of PrivilegeImportantCVSS:3.1 8.1 / 7.1
CVE-2026-69382Information DisclosureImportantCVSS:3.1 5.9 / 5.2
CVE-2026-69641Elevation of PrivilegeImportantCVSS:3.1 9.1 / 7.9

Note: CVE-2026-55007 is not addressed in the Exchange Server 2016 SU.

The Security Updates for each supported Exchange Server build are linked below:

ExchangeSU/HUDownloadBuildKBSupersedes
Exchange SE10Download15.2.2562.49KB5121608KB5121573
Exchange 2019 CU1511ESU215.2.1748.51KB5121609KB5121574
Exchange 2019 CU1414ESU215.2.1544.46KB5121610KB5121575
Exchange 2016 CU2325ESU215.1.2507.73KB5121611KB5121576

Fixed Issues

The SU resolves the following issues from previous updates:

Known Issues

Be aware of the following known issue after installing the SU:

Notes

  • Security updates are specific to the Cumulative Update level. You cannot apply the Exchange 2019 CU15 security update to Exchange 2019 CU14. When downloading, the security update might carry the same name for different Cumulative Updates. Microsoft now includes the KB article number as a reference, but I still tag the filename with the CU level for archival purposes, e.g., Exchange2019-CU15-KBxxxxxxx-x64-en.exe.
  • Like Cumulative Updates, Security Updates are cumulative, and you only need to install the latest SU for your CU.
  • Suppose you have deployed Exchange Management Tools to manage your on-premises Exchange Servers or installed the tools after removing the Last Exchange Server for recipient management. We recommend applying the Security Update.

Finally, as with any patch or update, test it in a test environment before deploying it to production. However, we do not recommend waiting for regular maintenance cycles for security updates; a more agile approach is preferable, and the ratings indicate the urgency level.

Security Updates Exchange 2016-SE (Aug2026)

The Exchange product group released the Augustus 2026 updates for Exchange Server SE, as well as Exchange 2019 and 2016. The Security Update for Exchange SE is available to the public. Security updates for Exchange 2019 and Exchange 2016 are available to organizations enrolled in the Extended Security Update Period 2 program.

The vulnerabilities addressed in these Security Updates for Exchange Server are:

VulnerabilityCategorySeverityRating
CVE-2026-65813Elevation of PrivilegeImportantCVSS:3.1 6.5 / 5.7
CVE-2026-62915Security Feature BypassImportantCVSS:3.1 6.5 / 5.7
CVE-2026-62914SpoofingImportantCVSS:3.1 7.3 / 6.4
CVE-2026-62913Remote Code ExecutionImportantCVSS:3.1 8.8 / 7.7
CVE-2026-62912Denial of ServiceImportantCVSS:3.1 6.5 / 5.7
CVE-2026-62911Elevation of PrivilegeImportantCVSS:3.1 8.0 / 7.0
CVE-2026-62910Elevation of PrivilegeCriticalCVSS:3.1 7.2 / 6.3
CVE-2026-55009Elevation of PrivilegeImportantCVSS:3.1 7.8 / 6.8

The Security Updates for each supported Exchange Server build are linked below:

ExchangeSU/HUDownloadBuildKBSupersedes
Exchange SE9Download15.2.2562.46KB5121573KB5103212
Exchange 2019 CU1510ESU Period 215.2.1748.49KB5121574KB5103213
Exchange 2019 CU1413ESU Period 215.2.1544.44KB5121575KB5103214
Exchange 2016 CU2324ESU Period 215.1.2507.72KB5121576KB5103215

Known Issue

Be aware of the following issue after installing these SU:

OWA Light

Starting with this SU, the OWA Light client will be permanently disabled. See related CVE-2026-62914 for more information. If you cannot install the August SU for some reason, it is recommended to disable OWA Light manually, e.g.

# To disable OWA Light in applicable Mailbox Policies
Set-OwaMailboxPolicy -OwaLightEnabled $false

# To disable OWA Light option in the OWA interface
Set-OwaVirtualDirectory -LogonPageLightSelectionEnabled $false

Notes

  • Security updates are specific to the Cumulative Update level. You cannot apply the Exchange 2019 CU15 security update to Exchange 2019 CU14. When downloading, the security update might carry the same name for different Cumulative Updates. Nowadays, Microsoft includes the KB article number as a reference, but I would still tag the filename with the CU level for archival purposes, e.g., Exchange2019-CU15-KBxxxxxxx-x64-en.exe.
  • Like Cumulative Updates, Security Updates are cumulative, and you only need to install the latest SU for your CU.
  • Suppose you have deployed Exchange Management Tools to manage your on-premises Exchange Servers or installed the tools after removing the Last Exchange Server for recipient management. It is recommended that you apply the Security Update.

On a final note, as with any patch or update, it is recommended that you test it in a test environment before deploying it to production. However, it is not recommended to wait for regular maintenance cycles for security updates; a more agile approach is preferable, and the ratings indicate the urgency level.

Security Updates Exchange 2016-SE (Jul2026)

The Exchange product group released the July 2026 updates for Exchange Server SE, as well as Exchange 2019 and 2016. The Security Update for Exchange SE is available to the public. Security updates for Exchange 2019 and Exchange 2016 are available to organizations enrolled in the Extended Security Update Period 2 program.

The vulnerabilities addressed in these Security Updates for Exchange Server are:

VulnerabilityCategorySeverityRating
CVE-2026-55005Remote Code ExecutionImportantCVSS:3.1 8.8 / 7.7
CVE-2026-55006Elevation of PrivilegeImportantCVSS:3.1 7.8 / 6.8
CVE-2026-55008SpoofingCriticalCVSS:3.1 9.6 / 8.3
CVE-2026-55009Elevation of PrivilegeImportantCVSS:3.1 7.8 / 6.8

The Security Updates for each supported Exchange Server build are linked below:

ExchangeSU/HUDownloadBuildKBSupersedes
Exchange SE8Download15.2.2562.45KB5103212KB5094139
Exchange 2019 CU159ESU Period 215.2.1748.48KB5103213KB5094140
Exchange 2019 CU1412ESU Period 215.2.1544.43KB5103214KB5094142
Exchange 2016 CU2323ESU Period 215.1.2507.71KB5103215KB5094144

Known Issue

Be aware of the following issue after installing these SU:

CVE-2026-42897

As a reminder, you may remove implemented mitigations for CVE-2026-42897. These mitigations could be deployed using Exchange Emergency Mitigation Service (EMS), or manually using the EOMT.ps1 script. If you used EMS, block the mitigation (M2.1.0) from re-applying, then remove its IIS rules. If you used the EOMT.ps1 script, use it to roll back the mitigation.

Notes

  • Security updates are specific to the Cumulative Update level. You cannot apply the Exchange 2019 CU15 security update to Exchange 2019 CU14. When downloading, the security update might carry the same name for different Cumulative Updates. Nowadays, Microsoft includes the KB article number as a reference, but I would still tag the filename with the CU level for archival purposes, e.g., Exchange2019-CU15-KBxxxxxxx-x64-en.exe.
  • Like Cumulative Updates, Security Updates are cumulative, and you only need to install the latest SU for your CU.
  • Suppose you have deployed Exchange Management Tools to manage your on-premises Exchange Servers or installed the tools after removing the Last Exchange Server for recipient management. In that case, it is recommended that you apply the Security Update.

On a final note, as with any patch or update, it is recommended that you test it in a test environment before deploying it to production. However, it is not recommended to wait for regular maintenance cycles for security updates; a more agile approach is preferable, and the ratings indicate the urgency level.

Security Updates Exchange SE, 2019 & 2016  (Jun2026)

The Exchange product group released the June 2026 Security Updates for Exchange Server SE, Exchange 2019, and Exchange 2016. There were no updates released in January, so if you missed those, you didn’t. The SE SU is available to the public. Security updates for Exchange 2019 and Exchange 2016 will be available to organizations enrolled in the Extended Security Update program.

The vulnerabilities addressed in these Security Updates for Exchange Server are:

VulnerabilityCategorySeverityRating
CVE-2026-42897Information DisclosureCriticalCVSS:3.1 8.1 / 7.5
CVE-2026-47631SpoofingImportantCVSS:3.1 8.1 / 7.1
CVE-2026-45583Remote Code ExecutionImportantCVSS:3.1 7.5 / 6.5
CVE-2026-45504Elevation of PrivilegeImportantCVSS:3.1 8.8 / 7.7
CVE-2026-45503Information DisclosureImportantCVSS:3.1 8.1 / 7.1
CVE-2026-45502Information DisclosureImportantCVSS:3.1 5.0 / 4.4
CVE-2026-45501SpoofingImportantCVSS:3.1 6.5 / 5.7
CVE-2026-45500SpoofingImportantCVSS:3.1 6.1 / 5.3

The Security Updates for each supported Exchange Server build are linked below:

ExchangeSU/HUDownloadBuildKBSupersedes
Exchange SE7Download15.2.2562.43KB5094139KB5074992
Exchange 2019 CU158ESU Period 215.2.1748.46KB5094140KB5074993
Exchange 2019 CU1411ESU Period 215.2.1544.41KB5094142KB5074994
Exchange 2016 CU2322ESU Period 215.1.2507.69KB5094144KB5074995

CVE-2026-42897

Be advised that these Security Updates do not remove any previously applied mitigations for CVE-2026-42897, whether through the EMS service (M2.1.0) or via manual configuration using the EOMT.ps1 script. More information about both options is described here. The recommendation is to keep mitigation in place. If you still wish to remove them, be advised that you need to take steps to prevent the mitigation from getting reapplied. These steps are also contained in the aforementioned article.

Fixed Issues

Other issues fixed in this update:

Emergency Mitigations & Flighting Service

Because of a server-side change, Exchange Server not patched with this June 2026 SU will stop processing emergency mitigations published after June 2026. As a result, their Emergency Mitigation Service (EMS) and Flighting Service cannot process any updates, and the Application event log will contain the following entries:

Event type: Error 
Event ID: 1008 
Event source: MSExchange Mitigation Service 
Exception encountered while fetching mitigations: This XML is not deemed safe to consume since Response xml’s leaf certificate is from unknown issuer or has EKU mismatch 

Any previously applied mitigations will continue to function.

Notes

  • Security updates are specific to the Cumulative Update level. You cannot apply the Exchange 2019 CU15 security update to Exchange 2019 CU14. When downloading, the security update might carry the same name for different Cumulative Updates. Nowadays, Microsoft includes the KB article number as a reference, but I would still tag the filename with the CU level for archival purposes, e.g., Exchange2019-CU15-KBxxxxxxx-x64-en.exe.
  • Like Cumulative Updates, Security Updates are cumulative, and you only need to install the latest SU for your CU.
  • Suppose you have deployed Exchange Management Tools to manage your on-premises Exchange Servers or installed the tools after removing the Last Exchange Server for recipient management. In that case, it is recommended that you apply the Security Update.

On a final note, as with any patch or update, it is recommended that you test it in a test environment before deploying it to production. However, it is not recommended to wait for regular maintenance cycles for security updates; a more agile approach is preferable, and the ratings indicate the urgency level.

Hotfix Update Exchange SE (May2026)

The Exchange product group released the May 2026 Hotfix update for Exchange Server SE. Hotfix updates do not contain security fixes, but address issues. They also might introduce or add support for functionality changes, such as dedicated Exchange hybrid application support.

ExchangeSU/HUDownloadBuildKBSupersedes
Exchange SE6Download15.2.2562.41KB5081755

Changes

The change introduced in this hotfix is:

Dedicated Exchange Hybrid Application

The dedicated Exchange hybrid application supports Exchange Web Services workflows, enabling rich coexistence functionality. This hotfix adds Graph-based workflow support for rich co-existence features between Exchange SE and Exchange Online. After installing the May 2026 update on all your Exchange SE servers, make sure you configure and enable the dedicated Exchange Hybrid application in Entra.

The support page lists WW as the tenant environment that currently supports Graph-based workflows, e.g. not GCC nor DoD. In addition, rich coexistence still partially uses EWS as shown in the following table taken from the dedicated hybrid application page.

FunctionalityEWS supportedGraph supported
Free/BusyYesYes
MailTipsYesPartial
(Automatic Replies only)
Profile PicturesYesYes
Move to Archive
(Archive Mailbox in cloud)
YesNo

Important: If you previously configured the dedicated Exchange Hybrid application, you need to rerun the ConfigureExchangeHybridApplication.ps1 script. This will enable the new Graph-based workflow. Detailed steps for accomplishing this are described here.

What about Exchange 2019 and Exchange 2016?

Exchange 2016 and 2019 are out of support and will not receive this update when you are part of the ESU program. Therefore, with the upcoming deprecation of Exchange Web Services in Exchange Online, you must keep allowing EWS in your tenant as of October 2026 – when EWS gets disabled – and make sure you plan to have migrated to Exchange SE by April 2027 for continued rich coexistence functionality, when EWS gets permanently disabled in Exchange Online.