Microsoft has released its July 2026 security updates for Exchange Server, addressing four vulnerabilities reported to Microsoft by security partners and found through Microsoft’s internal processes. The updates are available for Exchange Server Subscription Edition (SE) as well as legacy versions through the Extended Security Updates (ESU) program.
Affected Exchange Server Versions
The July 2026 security updates are available for the following Exchange Server versions:
- Exchange Server Subscription Edition (SE) RTM SU8 — KB5103212
- Exchange Server 2019 CU14 and CU15 — Available through ESU enrollment
- Exchange Server 2016 CU23 — Available through ESU enrollment
Addressed Vulnerabilities
The July 2026 SU resolve four CVEs affecting Exchange Server, as confirmed in Microsoft’s KB5103212 documentation:
- CVE-2026-55008 — Microsoft Exchange Server Spoofing Vulnerability
- CVE-2026-55005 — Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2026-55006 — Microsoft Exchange Server Elevation of Privilege Vulnerability
- CVE-2026-55009 — Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft’s Exchange Team hasn’t flagged any of these as publicly disclosed or under active exploitation, but a remote code execution flaw alongside two elevation-of-privilege bugs is nothing to sit on. Full technical detail on each CVE is available in Microsoft’s Security Update Guide by filtering on “Server Software” for Exchange SE, or “ESU” for Exchange 2016 and 2019.
Exchange Online customers are already protected against these vulnerabilities and don’t need to take any action, aside from patching any on-premises Exchange servers or Exchange Management tools workstations still present in a hybrid environment.
Cleaning Up After CVE-2026-42897
Installing the July SU does not automatically remove mitigations already applied for CVE-2026-42897 OWA spoofing vulnerability. If your servers are still running the M2.1.0 mitigation via the Exchange Emergency Mitigation (EM) Service, you’ll need to block it from re-applying and then remove its IIS rules yourself. If you deployed the standalone EOMT.ps1 script instead, you should roll that mitigation back manually.
Remove the mitigation M2.1.0 IIS rules.
If mitigation was applied using the downloadable EOMT script https://aka.ms/UnifiedEOMT:
Note: The EM Service change that tells the service “this build no longer needs the mitigation” is still rolling out, with an estimated completion date of July 16, 2026. Until that change reaches your environment, EM Service will keep re-applying the mitigation even after you’ve installed the July SU, so don’t be surprised if it doesn’t disappear on day one.
Health Checker Now Flags Deprecated Security Groups
Not directly tied to this SU, but worth noting: the Exchange Health Checker script has been updated to check for two very old, deprecated Active Directory security groups — Exchange Domain Servers and Exchange Enterprise Servers.
These groups have been deprecated since Exchange 2007, should no longer be in use, and can carry more permissions than modern Exchange security groups. If you’ve already decommissioned your last on-premises Exchange server, Microsoft recommends checking for and deleting these groups to prevent possible abuse, and considering a broader Active Directory cleanup while you’re at it.
Additional information can be found in this article.
Known Issue with This Release
Microsoft is tracking one known issue with the July SU: wrapper messages appearing in shared mailbox inboxes in hybrid environments.
Exchange Server 2016 and 2019 are out of support.
Exchange 2016 and 2019 Updates Are Available Only Under the ESU Program.
Customers enrolled in the Extended Security Update (ESU) Period 2 program are eligible to receive Exchange Server 2016 and 2019 security updates released between May and October 2026. Organizations not enrolled in ESU should migrate to Exchange Server Subscription Edition (SE) to continue receiving security updates.
Fortify Your Server with Messageware Security
Data breaches have increased by 72%, servers are compromised in under 90 minutes. Ensure you have multiple layers of security software protecting your Windows Servers.
Server Threat Guard (STG) for All Windows Servers: Next-gen server protection, providing detection, alerting, and response (MDR) to zero-day and server penetration cyber-attacks. No need to research complicated deployments and no learning curve to install and manage.
EPG Guard for Exchange Servers: Real-time security. Stop AD account lockouts, eliminate password attacks, intelligent GEO blocking, and prevent Exchange Server vulnerability probing.
Don’t leave your critical infrastructure vulnerable, be proactive and stay ahead of evolving threats.