-
Microsoft’s AI tools keep finding new security bugs in Exchange Server, and the team cannot stop fixing them long enough to ship the big update.
-
The Exchange Server SE Cumulative Update 1 has missed two deadlines already, first the first half of 2026, then the second half of 2026, and now has no date at all.
-
Microsoft says security fixes come first, and the big update will only ship when there is a calm month with no urgent patches to push out.
Microsoft promised Exchange Server administrators a major update. It was supposed to arrive before July 2026. Then the team pushed it to the second half of 2026. Now, according to a post from the Exchange team, there is no date at all. The reason is not laziness or poor planning. The reason is Microsoft’s own AI.
The company has been rolling out AI tools across its engineering teams. These tools scan software code and hunt for hidden security weaknesses. The Exchange Server team is one of many teams using them. And the tools are working, perhaps too well.
AI Keeps Finding Problems the Team Must Fix
Microsoft executives have spoken publicly about how the company is using AI to catch security flaws before attackers do. The Exchange team confirmed that this effort is now a company-wide push. Every team, including the Exchange team, is working through a growing list of reported problems.
Finding a bug is only step one. The team then has to check if the bug is a real security risk. After that, they have to recreate the problem on their own systems. Then they fix it. Then they tested everything again to make sure the fix did not break something else. That whole process takes time, and it repeats every single month.
The Exchange team has been shipping security patches every month since May 2026. June, July, and August followed. According to the team, this fast pace of security releases will continue. Security, they say, is the top priority right now.
The Big Update is Stuck Waiting for a Quiet Month
So where does that leave Cumulative Update 1, the big scheduled release that bundles all fixes together? The team says it is still being built. Each month, the team folds its latest security fixes into the internal CU1 build. The update is growing. But shipping it is the problem.
The team does not want to release CU1 and then immediately push another emergency security patch right after. That situation would create double the work for every IT administrator managing Exchange Server in their organisation. Those admins would have to install the big update and then turn around and install a patch on top of it almost straight away.
Making that situation worse, CU1 must include every single fix released since the original Exchange Server SE launch. That makes it a large and complex release. Testing it properly alongside a monthly security update at the same time would be extremely difficult, even for Microsoft’s own internal teams.
So the Exchange team is waiting. They need at least one calm month, a month where no urgent security fix needs to go out. Only then will they feel confident enough to ship CU1 without creating chaos for the people who have to install it.
What Administrators Should Do Right Now
The team’s message to Exchange Server administrators is simple. Keep your systems updated. If your organisation has not yet moved to Exchange Server SE, Microsoft is urging you to upgrade now. If you are already on Exchange Server SE, install every monthly security update as it arrives.
The importance of timely patching and breach disclosure is underscored by a lawsuit against commercial mortgage servicer Berkadia. A former senior security manager alleged the company suffered a March 2026 ShinyHunters breach that exposed names, Social Security numbers, and banking data, but failed to notify affected individuals for more than three weeks.
CU1 is still coming. The Exchange team confirmed it has not been cancelled or forgotten. There is just no date to announce yet. The AI tools that caused the delay are also the reason the software will be more secure when CU1 finally ships. Every bug the AI finds and the team fixes is one fewer weakness for attackers to exploit. For now, patience and regular patching are the best options available to Exchange administrators around the world.