Microsoft has released its June 2026 security updates for Exchange Server, delivering a permanent fix for the actively exploited CVE-2026-42897 Outlook Web Access vulnerability, along with additional vulnerabilities reported by security partners and found through Microsoft’s internal processes. The updates are available for Exchange Server Subscription Edition (SE) as well as legacy versions through the Extended Security Updates (ESU) program.
Affected Exchange Server Versions
The June 2026 security updates are available for the following Exchange Server versions:
- Exchange Server Subscription Edition (SE) — KB5094139
- Exchange Server 2019 CU14 and CU15 — Available through ESU enrollment
- Exchange Server 2016 CU23 — Available through ESU enrollment
CVE-2026-42897
CVE-2026-42897 is a high-severity cross-site scripting (XSS) spoofing vulnerability affecting Outlook Web Access on Exchange Server 2016, 2019, and SE. An attacker can exploit the flaw by sending a specially crafted email; if the recipient opens it in OWA, arbitrary JavaScript can be executed in their browser with no privileges required on the attacker’s part. The vulnerability has been actively exploited in the wild and was added to CISA’s Known Exploited Vulnerabilities catalog in May, with U.S. federal agencies ordered to patch within two weeks.
A temporary mitigation was pushed automatically via the Exchange Emergency Mitigation Service (EEMS) in May. The June SU delivers the permanent patch. Microsoft recommends keeping the existing EEMS mitigation in place after installing the update, as it provides an additional layer of protection while further improvements are released.
Keep EEMS Updated — July Deadline
Due to a service-side change, the Exchange Emergency Mitigation and Exchange Flighting services will be unable to use configuration files released in July 2026 unless the June SU is installed. Administrators should treat this update as time-sensitive. Unpatched servers will lose EEMS functionality when July configuration files are released.
Exchange Server 2016 and 2019 are out of support.
Exchange 2016 and 2019 Updates Are Available Only Under the ESU Program. Customers enrolled in the Extended Security Update (ESU) program are eligible to receive the June 2026 security updates for Exchange Server 2016 and 2019. Organizations not enrolled in ESU should migrate to Exchange Server Subscription Edition (SE) to continue receiving security updates.
Fortify Your Server with Messageware Security
Data breaches have increased by 72%, servers are compromised in under 90 minutes. Ensure you have multiple layers of security software protecting your Windows Servers.
Server Threat Guard (STG) for All Windows Servers: Next-gen server protection, providing detection, alerting, and response (MDR) to zero-day and server penetration cyber-attacks. No need to research complicated deployments and no learning curve to install and manage.
EPG Guard for Exchange Servers: Real-time security. Stop AD account lockouts, eliminate password attacks, intelligent GEO blocking, and prevent Exchange Server vulnerability probing.
Don’t leave your critical infrastructure vulnerable, be proactive and stay ahead of evolving threats.