Summary: Microsoft has no release date for Exchange Server SE Cumulative Update 1. The culprit: AI-assisted vulnerability scanning is finding more security issues than the Exchange team can validate and fix without disrupting a CU release. Keep applying monthly security updates. Stop waiting on a CU1 calendar date.

On August 13, 2026, the Exchange Server Team published “Where is Exchange SE CU1 anyway?”, a direct response to customer pressure over a missing release.

The timeline so far:

  • Original target: End of H1 2026
  • Revised target: H2 2026
  • Current status: No date. None offered.

This is the second time Microsoft has pushed the window back.

Reading our article? Try our product:

Full Protection for Windows Servers - Zero-Risk Trial

Why it’s delayed

Microsoft’s explanation boils down to one thing: AI-powered vulnerability discovery is outpacing the team’s ability to validate and fix what it finds.

Per the announcement, Microsoft is running AI tools across its product lines to surface potential security flaws. Exchange Server is one of many teams now working through a backlog that requires:

  • Validating whether a reported issue is a real vulnerability
  • Reproducing it
  • Fixing it
  • Regression-testing the fix
  • Shipping it — monthly

Exchange SE has received security updates every month since May 2026 (May, June, July, August), and Microsoft says that pace continues.

The problem for CU1 specifically: Microsoft is rolling each month’s security payload into the internal CU1 build as it goes, but won’t ship the CU until it hits a stretch without an urgent security patch competing for the same release. Shipping CU1 now, only to immediately follow it with a superseding security update, would mean admins doing the update work twice, once for the CU, once for the patch that invalidates it. Microsoft says that’s the outcome it’s trying to avoid, since CU1 has to include everything released since RTM in one clean, fully-tested package.

Exchange isn’t an isolated case. AI is speeding up discovery of bugs and vulnerabilities faster than humans can review and ship fixes for them. Exchange SE CU1 is just the most visible casualty right now.

What Microsoft is telling you to do

Straight from the source:

  1. Keep upgrading to Exchange Server SE if you haven’t already.
  2. If you’re already on SE, stay current on monthly security updates. Don’t wait on CU1 to be “secure.”
  3. Expect the increased monthly security-release cadence to continue. Security is being prioritized above the CU schedule, full stop.

Bottom line

Exchange SE CU1 isn’t canceled, Microsoft is explicit that it hasn’t been forgotten, and that active work continues on the internal build. But there is no date, no month, and no firm signal for when the security-patch volume will calm down enough to let it ship. Until Microsoft says otherwise, plan your Exchange operations around the monthly security update cycle, not around a CU1 release you can’t schedule against.

Fortify Your Server with Messageware Security

Data breaches have increased by 72%, servers are compromised in under 90 minutes. Ensure you have multiple layers of security software protecting your Windows Servers.

Server Threat Guard (STG) for All Windows Servers: Next-gen server protection, providing detection, alerting, and response (MDR) to zero-day and server penetration cyber-attacks. No need to research complicated deployments and no learning curve to install and manage.

EPG Guard for Exchange Servers: Real-time security. Stop AD account lockouts, eliminate password attacks, intelligent GEO blocking, and prevent Exchange Server vulnerability probing.

Don’t leave your critical infrastructure vulnerable, be proactive and stay ahead of evolving threats.