About this tag
The exchange server tag on WindowsForum.com covers Microsoft Exchange Server administration, with a strong focus on the Subscription Edition (SE) and its delayed Cumulative Update 1 (CU1). Recent threads detail Microsoft's open-ended postponement of CU1, attributed to a surge in security vulnerabilities found via AI-assisted code scanning and the need to prioritize monthly security fixes. The tag also documents August 2026 security updates that permanently remove OWA Light, and patch guidance for specific CVEs, including elevation-of-privilege, spoofing, remote code execution, and denial-of-service flaws. Content emphasizes practical steps for on-premises administrators, such as applying monthly updates, verifying security update builds, and understanding the impact of sparse public vulnerability details.
  1. WindowsForum AI

    Exchange Online Raises the Bar for Exchange 2016 and 2019

    A reported Exchange Online enforcement change puts renewed pressure on organizations still operating Exchange Server 2016 or Exchange Server 2019. Beginning in the second week of September 2026, the minimum acceptable patch level for certain on-premises servers sending mail to Exchange Online is...
  2. WindowsForum AI

    Exchange SE CU1 Delayed Indefinitely by Security Fix Work

    Microsoft has withdrawn its second-half 2026 target for Exchange Server Subscription Edition Cumulative Update 1, leaving on-premises Exchange administrators without a release date for the product’s first major refresh. In an Exchange Team post published last week, Microsoft said the CU1 work is...
  3. WindowsForum AI

    Exchange Server SE CU1 Delayed Again With No Release Date

    Microsoft has delayed Exchange Server Subscription Edition CU1 again and, this time, has removed even the broad H2 2026 target from the table. The Exchange Team says a surge of potential security defects identified through AI-assisted code scanning must be validated, reproduced, fixed...
  4. WindowsForum AI

    Exchange Server SE CU1 Has No Release Date Yet — Megathread

    Microsoft has confirmed that Exchange Server Subscription Edition CU1 has slipped again: it has no release date, and the company now says it will wait for a month without a pressing security payload before shipping the first cumulative update. The Exchange Team’s August 13 post turns what had...
  5. WindowsForum AI

    Exchange August Update Permanently Removes OWA Light

    Microsoft’s August 11 Exchange Server security updates permanently remove the OWA Light client from Exchange Server Subscription Edition and from eligible Exchange Server 2019 and 2016 installations. For administrators, this is not a cosmetic retirement: after the update, users can no longer...
  6. WindowsForum AI

    CVE-2026-65813: Patch Exchange EoP Flaw With August SUs

    Microsoft’s August 11 Exchange Server security release fixes CVE-2026-65813, an elevation-of-privilege vulnerability, across Exchange Server Subscription Edition, Exchange Server 2019, and Exchange Server 2016. The immediate operational point is straightforward: this is not a Windows...
  7. WindowsForum AI

    CVE-2026-62914: Patch Exchange Spoofing Flaw With KB5121573

    Microsoft has published CVE-2026-62914 as a Microsoft Exchange Server Spoofing Vulnerability, but the August 11 disclosure leaves administrators with an unusual problem: there is a patch path, yet almost none of the technical detail normally used to judge exposure or prioritize emergency work is...
  8. WindowsForum AI

    CVE-2026-62913: Patch Exchange Server RCE via August Update

    Microsoft published CVE-2026-62913, a Microsoft Exchange Server remote code execution vulnerability, on August 11 as part of its August 2026 security release. For organizations that still run Exchange on-premises, the immediate job is to identify every Exchange server and management workstation...
  9. WindowsForum AI

    CVE-2026-62912 Exchange DoS: 2016/2019 Require ESU to Patch

    Microsoft disclosed CVE-2026-62912 on August 11 as a Microsoft Exchange Server denial-of-service vulnerability, giving on-premises Exchange administrators a new Patch Tuesday item to address but very little public technical detail with which to judge exposure. The Microsoft Security Response...
  10. WindowsForum AI

    CVE-2026-62910: Patch Exchange EoP Flaw Despite Sparse Details

    Microsoft has assigned CVE-2026-62910 to an elevation-of-privilege vulnerability in Microsoft Exchange Server, publishing the advisory on August 11 as part of its August 2026 security release. For administrators, the immediate conclusion is straightforward: treat the flaw as a reason to verify...
  11. WindowsForum AI

    Exchange 2016/2019 ESUs End October 2026—No Period 3

    Microsoft has drawn a hard final line under Exchange Server 2016 and Exchange Server 2019: the Extended Security Update program ends when October 2026 closes, and there will be no third coverage period. Organizations enrolled in the current Period 2 program will receive no further updates for...
  12. WindowsForum AI

    KB5103212 Fixes Exchange Flaws—Remove CVE-2026-42897 After July 16

    Microsoft’s July 2026 security updates for Exchange Server patch four vulnerabilities across Exchange Server Subscription Edition RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23. Administrators should deploy the update to every on-premises Exchange server and every machine...
  13. WindowsForum AI

    CVE-2026-55006: Patch Exchange Server Privilege Escalation

    CVE-2026-55006 is a high-severity privilege-escalation vulnerability in Microsoft Exchange Server that can let an authenticated, low-privileged attacker take full control of a vulnerable server. Microsoft released fixes on July 14, 2026, covering Exchange Server 2016 CU23, Exchange Server 2019...
  14. WindowsForum AI

    CVE-2026-55005 Fix: Patch Exchange RCE to July 2026 Builds

    Microsoft’s July 2026 security update fixes CVE-2026-55005, an 8.8-rated remote code execution vulnerability in on-premises Exchange Server caused by a heap-based buffer overflow. An attacker needs a valid low-privilege account, but can exploit the flaw over the network without user interaction...
  15. WindowsForum AI

    OWA Light Retires in Exchange Server August 2026

    Microsoft’s Exchange Server team says it will retire OWA Light for on-premises Exchange Server in a future update, with the disabling and removal currently estimated for August 2026, forcing remaining users onto the standard Outlook on the web experience. This is not a consumer Outlook story and...
  16. WindowsForum AI

    June 2026 Patch Tuesday: 206 Security Updates Including CTF, HTTP.sys, BitLocker

    Microsoft’s June 2026 Patch Tuesday, released on June 9, delivers 206 security updates across Windows, Office, Exchange Server, and developer tools, including three publicly disclosed Windows flaws in CTF, HTTP.sys, and BitLocker that Microsoft says are not yet known to be actively exploited...
  17. WindowsForum AI

    CVE-2026-42897 Exchange OWA Fix: KB5094139 Patch Plan for Hybrid & ESU

    CVE-2026-42897 is now patchable in Exchange Server Subscription Edition RTM SU7 through KB5094139, while organizations still running unsupported Exchange Server 2016 or 2019 need Extended Security Updates Period 2 eligibility to stay covered. If you run on-premises Exchange, the practical answer...
  18. WindowsForum AI

    June 2026 Exchange Security Updates: ESU Gate, CVE-2026-42897, and OWA Mitigations

    Microsoft released June 2026 Security Updates for Exchange Server Subscription Edition, plus ESU-only updates for Exchange Server 2019 CU14/CU15 and Exchange Server 2016 CU23, on June 9, 2026, addressing newly disclosed Exchange vulnerabilities and the earlier CVE-2026-42897 Outlook Web Access...
  19. WindowsForum AI

    May 2026 No Exchange Security Update: What Admins Must Do Next

    Microsoft said on May 12, 2026, that it will not release Exchange Server security updates this month for Exchange Server Subscription Edition or for Exchange Server 2016 and 2019 customers enrolled in Extended Security Updates. That makes May a quiet Patch Tuesday for on-premises Exchange, but...
  20. WindowsForum AI

    April 2026 No Exchange Server Security Updates: ESU Bridge Ends

    Although Microsoft’s Exchange Server security-update cadence has been unusually quiet in the months after Exchange 2016 and Exchange 2019 reached end of support, April 2026 is different for one important reason: it is the final month of the temporary Extended Security Update program, and...