Microsoft has released its September 2026 security updates for Exchange Server, addressing nine vulnerabilities reported by security partners and found through Microsoft’s internal processes. The updates are available for Exchange Server Subscription Edition (SE), and for Exchange Server 2016 and 2019 through the Extended Security Update (ESU) program.
Affected Exchange Server Versions
The September 2026 security updates are available for the following Exchange Server versions:
- Exchange Server Subscription Edition (SE) RTM — KB5121608 (SU10)
- Exchange Server 2019 CU15 — KB5121609 (ESU enrollment required)
- Exchange Server 2019 CU14 — KB5121610 (ESU enrollment required)
- Exchange Server 2016 CU23 — KB5121611 (ESU enrollment required)
Nine Vulnerabilities Patched
This month’s release closes nine CVEs across Exchange Server. Microsoft has classified all of them as “Important,” with none reaching “Critical” severity. The highest-scoring issue is a spoofing vulnerability that lets an attacker impersonate another sender:
- CVE-2026-69356 — Spoofing (CVSS 9.3): allows an attacker to impersonate a different sender.
- CVE-2026-69641 — Elevation of Privilege (CVSS 9.1): lets an attacker gain elevated privileges within Exchange.
- CVE-2026-69355 — Remote Code Execution (CVSS 8.8): an authenticated attacker can execute code on the server.
- CVE-2026-55007 — Remote Code Execution (CVSS 8.1): a separate code-execution issue, not included in the Exchange 2016 CU23 SU.
- CVE-2026-69380 — Elevation of Privilege (CVSS 8.1): a missing-authorization flaw that could let a low-privilege, authenticated mailbox user read and send mail as other users.
- CVE-2026-69378 — Denial of Service (CVSS 7.5): allows an attacker to crash the service.
- CVE-2026-69361 — Spoofing (CVSS 6.5): a server-side request forgery issue that enables spoofing over the network.
- CVE-2026-69375 — Tampering (CVSS 6.5): allows unauthorized manipulation of data.
- CVE-2026-69382 — Information Disclosure (CVSS 5.9): allows disclosure of information that should be restricted.
Full details on each CVE are available in the Security Update Guide — filter on Server Software under Product Family for Exchange SE, and ESU under Product Family for Exchange 2016 and 2019.
Exchange Online Customers: No Action Needed
These vulnerabilities affect on-premises Exchange Server. Exchange Online customers are already protected and don’t need to do anything beyond updating any on-premises Exchange servers or workstations running the Exchange Management Tools in a hybrid environment.
Known Issues and Resolved Issues
Known issue in this release:
- Published calendars (.ics) return an HTTP 500 error for calendar applications. Microsoft says this will be addressed in a future update.
Issues resolved in this release:
- Wrapper messages appearing in the shared mailbox inbox in hybrid environments.
- Hybrid free/busy lookups over Microsoft Graph dropping the requester’s time zone.
Exchange Server 2016 and 2019 Are Out of Support
Exchange Server 2016 and 2019 have been out of mainstream support since October 2025. Only organizations enrolled in the Period 2 Extended Security Update (ESU) program are eligible for Exchange 2016 and 2019 security updates released between May and October 2026 — this September release included. Organizations that haven’t enrolled in ESU should plan to migrate to Exchange Server Subscription Edition (SE) to keep receiving security updates.
If you’ve already purchased Period 2 ESU and need help accessing this month’s updates, email ExchangeandSfBServerESUInquiry@service.microsoft.com.
How to Install the September 2026 Updates
- Inventory your servers. Run the Exchange Server Health Checker script to see which of your servers are behind on CUs, SUs, or other manual actions.
- Get to a supported CU. If you’re not already on SE RTM, Exchange 2019 CU14/CU15, or Exchange 2016 CU23, use the Exchange Update Wizard to plan your path from your current CU to your target CU.
- Install the September 2026 SU appropriate to your version.
- Reboot and verify. After setup finishes, reboot the server and confirm all Exchange services started correctly. Services stuck in a disabled state usually mean installation was interrupted.
- Troubleshoot if needed. If setup errors out, run the SetupAssist script, or consult Microsoft’s guidance for repairing failed Exchange CU/SU installations and resolving file-version errors during setup.
Sources: Microsoft — Released: September 2026 Exchange Server Security Updates; Microsoft Support KB articles 5121608, 5121609, 5121610, 5121611; MSRC Security Update Guide.
Fortify Your Server with Messageware Security
Data breaches have increased by 72%, servers are compromised in under 90 minutes. Ensure you have multiple layers of security software protecting your Windows Servers.
Server Threat Guard (STG) for All Windows Servers: Next-gen server protection, providing detection, alerting, and response (MDR) to zero-day and server penetration cyber-attacks. No need to research complicated deployments and no learning curve to install and manage.
EPG Guard for Exchange Servers: Real-time security. Stop AD account lockouts, eliminate password attacks, intelligent GEO blocking, and prevent Exchange Server vulnerability probing.
Don’t leave your critical infrastructure vulnerable, be proactive and stay ahead of evolving threats.