Microsoft has announced an indefinite delay for the first major cumulative update (CU1) to its Exchange Server Subscription Edition (SE), attributing the postponement to a surge in security vulnerabilities detected by artificial intelligence tools. The company stated that its Exchange team is currently overwhelmed with validating, reproducing, fixing, and testing these machine-generated security reports. This workload has directly impacted the development timeline for CU1, which was initially slated for release in the first half of 2026 and later pushed to the second half. Microsoft now refrains from committing to any specific release date.

The increased use of AI in vulnerability detection has led to a growing backlog of issues for the Exchange team. Each reported vulnerability requires a multi-step process: developers must confirm its existence, reproduce the issue, develop a solution, and then test the fix to ensure it does not introduce new errors. This process consumes resources that would otherwise be allocated to developing and testing CU1. Microsoft has also emphasized its commitment to prioritizing security in recent years, a stance reinforced by past criticisms from the U.S. government regarding Exchange security.

Despite the delay in CU1, Microsoft continues to address discovered vulnerabilities through its monthly security updates. These monthly fixes are also incorporated into the internal build of CU1. However, this continuous integration means that the internal version of CU1 is constantly evolving, making it difficult to reach a stable point for a final release.

Microsoft's strategy is to release CU1 only when it reaches a stable state and when there are no urgent security updates pending. This approach aims to prevent administrators from having to perform two major updates in quick succession, which could create additional work. The company also intends for CU1 to include all changes released since the initial manufacturing release of Exchange SE.

The situation highlights a challenge associated with AI-assisted security research: while AI tools can identify vulnerabilities more rapidly and in greater numbers, the subsequent human effort required for validation and remediation can strain development teams. Microsoft has previously indicated that AI could lead to more frequent fixes on Patch Tuesdays.

The delay in CU1 comes as support for Exchange Server 2016 and 2019 approaches its end-of-life. Organizations still running these older versions are "strongly urged" by Microsoft to update their Exchange Servers. Only customers enrolled in the Extended Security Update (ESU) program are eligible to receive security updates for Exchange Server 2016 and 2019 beyond their standard support lifecycle.

Microsoft's Exchange team acknowledged customer inquiries about the delay in a blog post titled "Where is Exchange SE CU1 anyway?". The company reassured customers that CU1 is still in development, stating, "Exchange SE CU1 is coming; we do not have a date to give you. But we did not forget about it."

The company has been releasing monthly security updates for Exchange Server Subscription Edition, Exchange Server 2019, and Exchange Server 2016. For instance, the August 2026 security updates addressed several vulnerabilities, including those affecting Exchange Server Subscription Edition RTM. These ongoing security updates are separate from the cumulative update, which bundles fixes and potentially introduces new features or architectural changes.