Skip to content
anavem.com logoanavem.com logo
AdvisoryMedium priorityNews

KB5094139 Patches 8 CVEs in Exchange Server SE Including Exploited Flaw

June 2026 security update for Exchange Server SE RTM patches 8 CVEs including CVE-2026-45583 RCE and CVE-2026-42897 OWA spoofing. At least one is actively exploited (CISA KEV). Max CVSS 8.8.

On this page

Exchange SE SU7 Patches 8 CVEs Including Exploited Flaw

Microsoft released KB5094139 on June 9, 2026, Security Update 7 for Exchange Server Subscription Edition RTM. Per the official KB, it patches 8 CVEs including CVE-2026-45583 (RCE), CVE-2026-42897 (OWA spoofing), CVE-2026-45504 (EoP), and four spoofing/info disclosure flaws. Per Senserva, at least one CVE is in the CISA KEV catalog (actively exploited). Max CVSS 8.8.

Per Mondoo, the fix for CVE-2026-45583 RCE is NOT included in the SU and requires separate mitigation steps. Parallel updates released for Exchange 2019 CU14/CU15 (KB5094140) and Exchange 2016 CU23 (KB5094144) via ESU. Exchange Online is not affected.

Active Exploitation Requires Priority Deployment

Per Senserva, this is a deploy-first update due to active exploitation. CVE-2026-42897 targets OWA, the most internet-exposed Exchange component. Unpatched on-premises Exchange servers remain a top target for nation-state and ransomware groups. Superseded by KB5103212 (July SU8).

Exchange Server SE, 2019, and 2016

Exchange Server SE RTM. Exchange 2019 CU14/CU15 and 2016 CU23 via ESU. Install from elevated prompt. Run HealthChecker after installation. Follow separate CVE-2026-45583 mitigation instructions.

Response

Response status: No response

Patch available: No

Workaround available: No

Reader actions
Was this helpful?
Rate this articleRate
2 readers viewed this article

Reader reviews

Rate this articleBe the first to rate
No written reviews yetRate the article above, or be the first to share your experience.