Exchange Server SE: Microsoft Explains Why CU1 Still Hasn’t Arrived
Time goes by and the first cumulative update for Exchange Server SE still hasn't arrived. So where is CU1? Microsoft has finally explained itself publicly on the matter, and here is the culprit: the flood of vulnerabilities reported by the company's AI tools, which is overwhelming the development teams. No release date has been announced for CU1, however. Here's what we know.
Since the general availability of Exchange Server SE on July 1, 2025, this new version of Microsoft's messaging server has been waiting for its first cumulative update (also known as CU1). More than a year later, administrators are still waiting. The months go by, and yet this update still hasn't arrived. The article titled "Where is Exchange SE CU1 anyway?" and published on August 13, 2026, provides some answers.
Regarding this famous CU1, the Exchange team at Microsoft states: "In the past, we had said it would be released by the end of the first half of calendar year 2026, and then that deadline was pushed back to the second half of 2026. What is the problem? Where is CU1?", writes the Redmond company, echoing its customers' concerns.
AI Is Filling the Backlog, and Security Comes First
In reality, Microsoft's teams are drowning in security vulnerability reports detected by its own AI systems. "Over the past few months, several Microsoft leaders have made statements explaining how Microsoft uses various AI tools to help find vulnerabilities in our products", the article recalls.
By the way, I have already presented MDASH, Microsoft's multi-agent system dedicated to vulnerability discovery, and explained how AI is triggering a historic tsunami of security flaws across the software industry. The only catch is that a vulnerability detected by AI cannot be fixed with the snap of a finger, even if AI can also suggest patches.
The Exchange team says it is necessary to "validate that these are indeed real security issues, reproduce them, fix them, test for regressions and post-patch issues, and publish updates every month". A full cycle, every month.
Microsoft is therefore trying to keep pace with security patches: Exchange Server received security updates in May, June, July, and August 2026, meaning four consecutive months. And Microsoft warns that this pace will continue. The Redmond company says it places security above all else. That is understandable, and that is why CU1 is taking so long.
No Release Date for Exchange Server SE CU1
Microsoft says it is working on CU1 in parallel, without giving a date. In reality, CU1 is waiting for a window of opportunity: a month without any urgent security patching needs. Given the number of vulnerabilities fixed by Microsoft in recent months, one has to wonder whether CU1 will even be released in 2026... Especially since Microsoft wants to limit risks, including for customers.
"We really do not want to release a new CU1 only to immediately replace it with security updates, as that would double the update workload for many enterprise administrators.", we can read.
Microsoft has not forgotten CU1 for Exchange Server SE, but there is no date: it could arrive next month or in 6 months. The good news is that Exchange Server is indeed receiving the necessary security patches. The bad news is that Exchange Server SE is not evolving. In fact, the RTM version of Exchange Server SE is, with a few exceptions (license agreement, product name, and build number), the code from Exchange Server 2019 CU15. Microsoft states this clearly in its documentation: new features only arrive starting with CU1. Until it is released, Exchange Server SE remains, technically, Exchange 2019 repackaged under a subscription model.
What do you think?


