The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Microsoft Exchange Server flaws can put data and services at risk, but the impact depends on the specific vulnerability and how Exchange is deployed. Administrators should identify their exact server version and build, follow Microsoft’s update guidance for that product, and treat any emergency mitigation as temporary protection—not a substitute for installing the security update.
What kinds of risk do Exchange flaws create?
Microsoft’s Exchange security updates include vulnerabilities classified as spoofing, information disclosure, elevation of privilege, and remote code execution. Those categories describe different potential consequences; they do not mean that every flaw exposes mailbox contents or affects every organization in the same way. The relevant advisory and the server’s configuration determine the risk.
Start by distinguishing an on-premises Exchange Server from Exchange Online and a hybrid deployment. The update pages discussed below name particular server editions and builds, so a notice for one version should not be treated as proof that another version is affected—or protected.
Which Exchange servers and updates are covered?
| Deployment or version | What the cited guidance establishes | What to do |
|---|---|---|
| Exchange Server 2019 CU14 | Microsoft’s October 2, 2026 version 2 security update is KB5129957. It lists CVE-2026-96940, CVE-2026-55007, CVE-2026-69355, CVE-2026-69356, CVE-2026-69361, CVE-2026-69375, CVE-2026-69378, CVE-2026-69382, and CVE-2026-69641. Microsoft also identifies a known issue in which published calendars can return HTTP 500 errors for calendar applications. | Check the installed edition, cumulative update, and build against Microsoft’s KB5129957 guidance. Review its known issue if your organization uses published calendars. |
| Exchange Server Subscription Edition (SE) | Microsoft’s June 9, 2026 update page lists CVE-2026-42897, CVE-2026-45500, CVE-2026-45501, CVE-2026-45502, CVE-2026-45503, CVE-2026-45504, CVE-2026-47631, and CVE-2026-45583. The page says the fix for CVE-2026-45583 is not included in that update and directs readers to the CVE documentation. | Use the Exchange SE update page and the linked CVE documentation to determine the applicable fix for your installed build. |
| Exchange Online | The cited server update pages address named Exchange Server editions and builds. They do not establish that Exchange Online customers need to install an on-premises server update. | Do not apply on-premises instructions to the cloud service by assumption. For hybrid environments, assess the on-premises server and identity configuration separately. |
The entries above are specific dated examples, not a substitute for checking Microsoft’s current guidance for the exact product and build in your environment.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match#1 Best Overall
What should an administrator do first?
- Inventory the deployment. Record whether Exchange is on-premises, Exchange Online, or hybrid, along with the installed Exchange edition, cumulative update, and build. Determine whether a hybrid configuration was used in the past, not only whether it is active today.
- Match the server to the advisory. Compare that inventory with Microsoft’s update documentation and the CVE-specific guidance. Do not infer that a server is covered because a different Exchange version received an update.
- Install the applicable security update. Follow Microsoft’s instructions for the exact product and build, then verify that the update is installed. A temporary mitigation being present is not evidence that the security update has been applied.
- Review hybrid identity exposure. If the organization has a hybrid deployment or previously configured one, follow Microsoft’s and CISA’s instructions for the relevant hybrid vulnerability, including any required hotfix or application configuration changes and service-principal cleanup review.
- Validate and harden. Run Microsoft Exchange Health Checker as directed by the applicable guidance, and consult the joint government Exchange Server Security Best Practices for on-premises hardening.
Why hybrid Exchange needs a separate identity review
CISA’s August 2025 alert on CVE-2025-53786 describes a risk to identity integrity in an organization’s Exchange Online service when an attacker already has administrative access to a vulnerable on-premises Exchange server and the hybrid configuration is affected. This is not a claim that the flaw alone gives an unauthenticated attacker access to every organization’s cloud mailboxes.
CISA advised organizations to assess potentially affected hybrid deployments, install Microsoft’s April 2025 hotfix updates and follow the dedicated hybrid application configuration instructions where applicable, review Service Principal Clean-Up Mode even if hybrid Exchange had been used previously, and run Exchange Health Checker. See the CISA alert for CVE-2025-53786 for the applicable details.
Rank #2
CISA’s August 2025 alert said Microsoft had reported no observed exploitation at that time. That dated statement should not be read as a current threat-status assessment or as a reason to defer remediation.
Are emergency mitigations enough?
No. Microsoft’s Exchange Emergency Mitigation service is an optional service for on-premises Exchange Servers. It checks Microsoft’s Office Config Service hourly, validates signed mitigation configuration, and can apply temporary protections involving URL Rewrite, Exchange services, or application pools. Mitigations can affect functionality, so administrators should follow Microsoft’s instructions for their environment.
Microsoft explicitly says these mitigations do not replace security updates. Use them as interim protection where appropriate, and independently verify installation of the applicable update. Details are in Microsoft’s Exchange Emergency Mitigation Service documentation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How support status affects the response
Microsoft says Exchange Server 2016 and Exchange Server 2019 have reached end of support. Its October 2, 2026 update page says organizations enrolled in Period 2 Extended Security Updates are eligible to receive released security updates through the end of October 2026. Organizations that are not enrolled should migrate to Exchange Server Subscription Edition to continue receiving the latest security updates.
Rank #4
For an organization still operating Exchange 2016 or 2019, verify its ESU eligibility rather than assuming that an older server continues to receive updates. Plan the move to a supported version as part of remediation; an update for one eligible build does not change the product’s end-of-support status.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems

