🚨 Actively exploited Exchange Server zero-day is now patched. Refer to the Microsoft June updates section and links below.
Messageware June Releases:
- Messageware AttachView SE/2019, 2016
AttachView includes important security updates in our attachment viewing technology. - Messageware EPG SE/2019, 2016
EPG includes important Spamhaus and Geolocation updates.
Get secure with our products:
- Server Security and Health monitoring (STG)
- Exchange Server SE Protection (EPG)
- Test us out (Free Trials)
Product updates are available at:
https://www.messageware.com/support/
Compatibility Matrix for matching versions:
https://www.messageware.com/pdf/Compatibility-Matrix.pdf
Server Threat Guard
Server Threat Guard delivers real-time security threat detection and intelligent server health monitoring so your team can prevent issues before they become outages. It runs directly on the server with no additional hardware, keeping all analysis local for maximum performance and privacy.
Highlights:
- Real-time health event detection: Automatically surfaces critical and error-level conditions
- Deep system monitoring: Services, tasks, IIS, registry, event logs, and more
- Intelligent AutoLearn: Reduces alert fatigue so you can focus on real threats
- Intelligent alerting and reporting: Instant threat notifications and daily server health summaries
- All local operations: Zero cloud dependency
If you haven’t tried STG yet, it’s easier than you think. No complicated setup — just deploy and you’re protected.
Start your free trial:
https://pages.messageware.com/get-protected-with-server-threat-guard
June updates for Exchange Server (SUs for SE/2019/2016)
Microsoft’s June 2026 Patch Tuesday includes critical security updates for Exchange Server, addressing multiple CVEs.
The June 2026 SUs are available for the following versions:
- Exchange Server Subscription Edition (SE) RTM SU7 (KB5094139)
- Exchange Server 2019 Cumulative Update 15 (CU15)
- Exchange Server 2019 Cumulative Update 14 (CU14)
- Exchange Server 2016 Cumulative Update 23 (CU23)
The Exchange Server team released the June 2026 SU for Exchange Server SE, addressing vulnerabilities reported by security partners, found internally, and CVE-2026-42897. After installing, keep the CVE-2026-42897 mitigation in place as it provides additional server protection. This update is also required for continued use of EEMS and Feature Flighting. See the team’s blog post for details.
🚨 Exchange 2016 and 2019 updates are available only under the ESU program.
Actively Exploited Exchange Server Zero-Day Now Patched
Microsoft has patched a high-severity Exchange Server vulnerability (CVE-2026-42897) that was actively exploited in cross-site scripting attacks against Outlook Web Access users. The flaw affects Exchange Server 2016, 2019, and SE, and could be triggered by a specially crafted email allowing arbitrary JavaScript to execute in the victim’s browser with no attacker privileges required.
Microsoft is urging admins to install the June 2026 Security Update immediately and to leave the EEMS mitigation in place for additional protection.
For a full list of CVEs addressed in this update, see the release notes.
Fortify Your Server with Messageware Security
Data breaches have increased by 72%, servers are compromised in under 90 minutes. Ensure you have multiple layers of security software protecting your Windows Servers.
Server Threat Guard (STG) for All Windows Servers: Next-gen server protection, providing detection, alerting, and response (MDR) to zero-day and server penetration cyber-attacks. No need to research complicated deployments and no learning curve to install and manage.
EPG Guard for Exchange Servers: Real-time security. Stop AD account lockouts, eliminate password attacks, intelligent GEO blocking, and prevent Exchange Server vulnerability probing.
Don’t leave your critical infrastructure vulnerable, be proactive and stay ahead of evolving threats.