Microsoft has confirmed that Exchange Server Subscription Edition CU1 has slipped again: it has no release date, and the company now says it will wait for a month without a pressing security payload before shipping the first cumulative update. The Exchange Team’s August 13 post turns what had been a second-half-of-2026 target into an open-ended hold, leaving administrators on Exchange SE RTM to continue applying monthly updates rather than plan around a CU1 deployment window.

The explanation is straightforward, if less reassuring than a date. Microsoft says Exchange engineering is prioritizing vulnerability validation, fixes, regression testing, and monthly releases as the company expands its use of AI-assisted security research. CU1 is being continuously rebuilt with those security fixes, but Microsoft does not want customers to install a large cumulative update only to have it immediately followed by another security update.

Microsoft Learn’s Exchange build history confirms the practical result: the current release remains Exchange Server SE RTM Aug26SU, released August 11, 2026, build 15.2.2562.46. There is no CU1 build, download, or release note. For organizations waiting for the first major post-RTM servicing milestone, the usable answer is therefore simple: CU1 is still in development, and nobody outside Microsoft can responsibly schedule around it.

IT administrator monitors Exchange Server subscription status, security updates, vulnerabilities, and system health.The schedule has moved from a date to a condition​

CU1 was once expected in late 2025. Microsoft subsequently moved it to the first half of 2026, then changed the public timeline in May to the second half of 2026. The August 13 Exchange Team post acknowledges both missed expectations but provides no replacement month, quarter, preview program, or build number.

Instead, the release condition is now a “reasonable stable point” and a month in which the team does not need to deliver urgent security fixes. That is materially different from saying the update is targeted for September, October, or any other point in the second half of the year. A month without a pressing payload could arrive soon; it could also be delayed by the very monthly security cadence Microsoft says will continue.

This is not simply a semantic change. Exchange cumulative updates are substantial maintenance events: they bundle prior fixes into a new baseline and can introduce platform, authentication, setup, management, or coexistence changes. Microsoft’s own Exchange update guidance says that a newly installed CU must also receive the latest applicable security update. The team’s stated aim is to avoid putting administrators through exactly that sequence—deploy a CU, then deploy an SU almost immediately afterward.

The problem is that the condition Microsoft selected is external to a conventional product-release calendar. CU1 will ship when the security queue permits it, rather than when the previously advertised roadmap says it should. That is a defensible quality decision for a mail server product with a long history of high-impact vulnerabilities, but it leaves customers without the planning certainty that a cumulative update schedule is supposed to provide.


The latest build is still RTM, despite four months of servicing​

The Exchange SE branch has received meaningful servicing since May, but it remains labeled RTM. Microsoft’s build record lists the May 7 update as a Hotfix Update, followed by June, July, and August Security Updates. The August 11 release advanced the SE build to 15.2.2562.46.

That record also exposes a small but revealing imprecision in Microsoft’s explanation. The Exchange Team described a run of security updates in May, June, July, and August, but Microsoft Learn classifies the May 7 package as an HU, not an SU. The distinction matters for change control. A Hotfix Update can include functional fixes as well as security work; in this case, the May 2026 HU introduced Microsoft Graph support for selected hybrid capabilities, including free/busy information, profile-picture sharing, and part of MailTips functionality.

Administrators should therefore avoid treating the intervening releases as routine, interchangeable monthly patches. The May package introduced an on-premises feature change, while the later SUs kept the RTM baseline current. CU1, when it arrives, is expected to consolidate the accumulated servicing work into a new installation baseline. It will not erase the need to review the release notes and deploy any later SU that applies to the new CU.

Microsoft’s public build table also makes the immediate operational position easy to verify. A fully updated SE installation should show the August 2026 security update rather than a hypothetical CU1 version. The version to look for is 15.02.2562.046 on the executable version record.

CU1’s delay also delays several transition points​

The first Exchange SE release was intentionally conservative. Microsoft previously described SE RTM as essentially a rebranded continuation of Exchange Server 2019 CU15, designed to make in-place upgrades comparatively low risk. CU1 was expected to be where the Subscription Edition line began to show more consequential changes.

Microsoft’s earlier Exchange roadmap associated CU1 with server-to-server Kerberos as the default authentication direction, an Admin API intended to modernize remote management, eventual Remote PowerShell deprecation, an updated Visual C++ redistributable, and removal of UCMA 4.0 support. Microsoft had also discussed Outlook Anywhere retirement, though it later said that deprecation needed more time after customers identified blockers.

None of those older plans is a promise for the eventual CU1 build. Microsoft has not published a refreshed CU1 feature list alongside this delay notice, and it would be a mistake to assume every previously announced item will ship unchanged. The missing release notes matter more now because CU1 has evolved while Microsoft has rolled each security payload into its internal build.

There is also a licensing consequence. Microsoft has said SE RTM accepts Exchange Server 2019 product keys as a transition measure, while Exchange SE-specific server keys are planned to arrive with CU1. Organizations that moved to SE RTM should use the extra time to confirm that their licensing entitlement is visible in the Microsoft 365 admin center and that their Software Assurance or qualifying subscription position is in order. A delayed CU1 does not alter the subscription licensing requirement; it postpones the point at which the SE-specific key transition is expected to become operationally relevant.

For Exchange 2016 and Exchange 2019 customers, the delay does not restore normal support. Microsoft Learn lists both versions as out of support, with post-2025 security updates available only to customers enrolled in the Extended Security Update program. Microsoft continues to steer non-ESU customers toward Exchange SE for current security servicing.


What Exchange administrators should do while CU1 is absent​

The right response is not to pause patching until CU1 arrives. Microsoft’s message specifically tells SE customers to remain current, and the latest available SE package is the August 2026 SU.

A sensible near-term plan is limited but concrete:

  • Keep Exchange SE RTM on the August 2026 security level, build 15.2.2562.46, after completing normal lab validation and change-control procedures.
  • Verify the installed update with the Exchange HealthChecker script or the ExSetup.exe file version rather than relying only on Get-ExchangeServer, because Microsoft documents that the latter shows the CU baseline but not installed SUs or HUs.
  • Do not schedule a production migration, a maintenance freeze, or a licensing-key change around an assumed CU1 date. Microsoft has given no date, and its new condition means the next pressing security issue could move the release further.
  • Inventory dependencies that could be affected by the eventual CU1 changes, especially Exchange management scripts using Remote PowerShell, applications tied to legacy unified communications components, and any remaining Outlook Anywhere or RPC over HTTP assumptions.
  • Preserve clean rollback, backup, and DAG maintenance procedures for the current monthly update cadence. CU1 may reduce the number of packages needed to establish a new baseline, but it will remain a major Exchange servicing event requiring its own testing.

Microsoft says its objective is to spare customers “double the update work.” In the short term, though, the work has not disappeared; it has shifted. Exchange administrators must keep installing the RTM security updates while separately maintaining CU1 readiness without a calendar date to anchor the effort.

As of August 14, the first SE cumulative update is still absent, the latest supported SE build remains the August 11 RTM security update, and Microsoft’s only timing commitment is that CU1 will ship after security pressure eases enough for the team to stabilize it.