
The Exchange product group released the September 2026 updates for Exchange Server SE, Exchange 2019, and Exchange 2016. The Security Update for Exchange SE is publicly available. Security updates for Exchange 2019 and Exchange 2016 are available to organizations enrolled in the Extended Security Update Period 2 program.
The vulnerabilities addressed in these Security Updates for Exchange Server are:
Note: CVE-2026-55007 is not addressed in the Exchange Server 2016 SU.
The Security Updates for each supported Exchange Server build are linked below:
Fixed Issues
The SU resolves the following issues from previous updates:
Known Issues
Be aware of the following known issue after installing the SU:
Notes
- Security updates are specific to the Cumulative Update level. You cannot apply the Exchange 2019 CU15 security update to Exchange 2019 CU14. When downloading, the security update might carry the same name for different Cumulative Updates. Microsoft now includes the KB article number as a reference, but I still tag the filename with the CU level for archival purposes, e.g., Exchange2019-CU15-KBxxxxxxx-x64-en.exe.
- Like Cumulative Updates, Security Updates are cumulative, and you only need to install the latest SU for your CU.
- Suppose you have deployed Exchange Management Tools to manage your on-premises Exchange Servers or installed the tools after removing the Last Exchange Server for recipient management. We recommend applying the Security Update.
Finally, as with any patch or update, test it in a test environment before deploying it to production. However, we do not recommend waiting for regular maintenance cycles for security updates; a more agile approach is preferable, and the ratings indicate the urgency level.
Related

