06/11/2026
π’ Microsoft released the June 2026 Exchange Server Security Updates on June 8, 2026.
Affected versions:
β’ Exchange Server SE
β’ Exchange Server 2019 (ESU Period 2 enrollees only)
β’ Exchange Server 2016 (ESU Period 2 enrollees only)
CVEs addressed:
β’ CVE-2026-42897 β cross-site scripting (XSS) vulnerability
β’ Additional vulnerabilities identified through Microsoft's internal security processes
Critical deadline β July 2026:
Servers not running the June 2026 SU or newer will lose access to Emergency Mitigation (EM) service configurations and Feature Flighting updates starting July 2026.
ESU note:
Exchange 2016 and 2019 SUs are restricted to organisations enrolled in the Period 2 ESU program (MayβOctober 2026). Organisations not enrolled should prioritise migration to Exchange Server SE.
CVE-2026-42897 mitigation:
Existing mitigations are not automatically removed by the SU. Microsoft advises keeping them in place until further notice.
Read more: https://www.messageware.com/patch-tuesday-exchange-server-security-updates-for-june-2026/
Microsoft released June 2026 Exchange Server security updates addressing CVE-2026-42897, a critical Outlook Web Access vulnerability.