Security Updates Exchange SE, 2019 & 2016  (Jun2026)

The Exchange product group released the June 2026 Security Updates for Exchange Server SE, Exchange 2019, and Exchange 2016. There were no updates released in January, so if you missed those, you didn’t. The SE SU is available to the public. Security updates for Exchange 2019 and Exchange 2016 will be available to organizations enrolled in the Extended Security Update program.

The vulnerabilities addressed in these Security Updates for Exchange Server are:

VulnerabilityCategorySeverityRating
CVE-2026-42897Information DisclosureCriticalCVSS:3.1 8.1 / 7.5
CVE-2026-47631SpoofingImportantCVSS:3.1 8.1 / 7.1
CVE-2026-45583Remote Code ExecutionImportantCVSS:3.1 7.5 / 6.5
CVE-2026-45504Elevation of PrivilegeImportantCVSS:3.1 8.8 / 7.7
CVE-2026-45503Information DisclosureImportantCVSS:3.1 8.1 / 7.1
CVE-2026-45502Information DisclosureImportantCVSS:3.1 5.0 / 4.4
CVE-2026-45501SpoofingImportantCVSS:3.1 6.5 / 5.7
CVE-2026-45500SpoofingImportantCVSS:3.1 6.1 / 5.3

The Security Updates for each supported Exchange Server build are linked below:

ExchangeSU/HUDownloadBuildKBSupersedes
Exchange SE7Download15.2.2562.43KB5094139KB5074992
Exchange 2019 CU158ESU Period 215.2.1748.46KB5094140KB5074993
Exchange 2019 CU1411ESU Period 215.2.1544.41KB5094142KB5074994
Exchange 2016 CU2322ESU Period 215.1.2507.69KB5094144KB5074995

CVE-2026-42897

Be advised that these Security Updates do not remove any previously applied mitigations for CVE-2026-42897, whether through the EMS service (M2.1.0) or via manual configuration using the EOMT.ps1 script. More information about both options is described here. The recommendation is to keep mitigation in place. If you still wish to remove them, be advised that you need to take steps to prevent the mitigation from getting reapplied. These steps are also contained in the aforementioned article.

Fixed Issues

Other issues fixed in this update:

Emergency Mitigations & Flighting Service

Because of a server-side change, Exchange Server not patched with this June 2026 SU will stop processing emergency mitigations published after June 2026. As a result, their Emergency Mitigation Service (EMS) and Flighting Service cannot process any updates, and the Application event log will contain the following entries:

Event type: Error 
Event ID: 1008 
Event source: MSExchange Mitigation Service 
Exception encountered while fetching mitigations: This XML is not deemed safe to consume since Response xml’s leaf certificate is from unknown issuer or has EKU mismatch 

Any previously applied mitigations will continue to function.

Notes

  • Security updates are specific to the Cumulative Update level. You cannot apply the Exchange 2019 CU15 security update to Exchange 2019 CU14. When downloading, the security update might carry the same name for different Cumulative Updates. Nowadays, Microsoft includes the KB article number as a reference, but I would still tag the filename with the CU level for archival purposes, e.g., Exchange2019-CU15-KBxxxxxxx-x64-en.exe.
  • Like Cumulative Updates, Security Updates are cumulative, and you only need to install the latest SU for your CU.
  • Suppose you have deployed Exchange Management Tools to manage your on-premises Exchange Servers or installed the tools after removing the Last Exchange Server for recipient management. In that case, it is recommended that you apply the Security Update.

On a final note, as with any patch or update, it is recommended that you test it in a test environment before deploying it to production. However, it is not recommended to wait for regular maintenance cycles for security updates; a more agile approach is preferable, and the ratings indicate the urgency level.

TechEd North America 2012 sessions

With the TechEd North America 2012 event still running, recordings and slide decks of finished sessions are becoming available online. Here’s an overview of the Exchange-related sessions:


ForeFront Update Center

Want to check if you’re running the latest Service Pack or Rollup for your ForeFront components? The ForeFront team has published a page where all ForeFront components, related technologies included, are listed, including information on the latest Service Pack, Rollup, version number as well as a link to product guidance.

The ForeFront Update Center as it is called contains information on the following products:

  • Microsoft Forefront Protection 2010 for Exchange Server
  • Forefront Protection 2010 for SharePoint
  • Microsoft Forefront Client Security
  • Microsoft Forefront Security for Exchange Server
  • Forefront Security for SharePoint
  • Forefront Server Security Management Console
  • Forefront Security for Office Communications Server
  • Antigen 9.0 for Exchange
  • Antigen 8.0 for Microsoft SharePoint Portal Server
  • Forefront Threat Management Gateway 2010
  • Internet Security and Acceleration Server 2006
  • Forefront Unified Access Gateway 2010
  • Intelligent Application Gateway 2007

You can find the page here.

Forefront Protection for Exchange Server survey

The ForeFront Server Protection team is looking for feedback on the Forefront Protection for Exchange Server:

Although we just shipped Forefront Protection for Exchange Server 2010, we are already hard at work planning the next release. To that end, we are very interested in hearing feedback on your experience deploying and managing your current antimalware solution for Exchange. Please take 5-10 minutes to answer the survey questions. This type of feedback directly impacts future product decisions and we would appreciate your valuable input.

To contribute you can enter the survey here.

Microsoft Forefront Protection 2010 for Exchange Server Best Practices Analyzer

Today Microsoft released the (take a deep breath) Microsoft Forefront Protection 2010 for Exchange Server Best Practices Analyzer (v11.0), or FPE 2010 BPA for short. The FPE 2010 BPA examines servers running ForeFront Protection 2010 for Exchange Server and checks the system configuration as well as the product configuration. Any settings or combination of settings that do not conform to FPE 2010 best practices are reported, enabling administrators to easily identify and address possible issues.

I assume everbody knows how these BPAs work, but in case you don’t proceed as follows:

  1. Download the FPE 2010 BPA from this location;
  2. Install the ForeFront Server Protection Best Practices Analyzer (FPBPA) on a server containing ForeFront Security 2010 for Exchange Server;
  3. Use the default settings and have FPBPA retrieve updates from the internet when required;
  4. Start FPBPA. It will check for online updates;
  5. Click Select options for a new scan;
  6. Enter a scan label, i.e. Initial FPBPA Scan, and click Start Scanning. FPBPA will now scan your ForeFront environment;
  7. When Scanning Completed click View a report of this Best Practices scan.

As you can see from the first issue, I still need to install the RTM 🙂  The second issue is about a non-configured critical error notification, i.e.  it has no no e-mail recipient specified. The other two issues are about possible misconfiguration of the number of scan processes (as FPE 2010 BPA states, the recommended setting is twice the number of CPUs here).