KB5094139 Patches 8 CVEs in Exchange Server SE Including Exploited Flaw
June 2026 security update for Exchange Server SE RTM patches 8 CVEs including CVE-2026-45583 RCE and CVE-2026-42897 OWA spoofing. At least one is actively exploited (CISA KEV). Max CVSS 8.8.

On this page
Exchange SE SU7 Patches 8 CVEs Including Exploited Flaw
Microsoft released KB5094139 on June 9, 2026, Security Update 7 for Exchange Server Subscription Edition RTM. Per the official KB, it patches 8 CVEs including CVE-2026-45583 (RCE), CVE-2026-42897 (OWA spoofing), CVE-2026-45504 (EoP), and four spoofing/info disclosure flaws. Per Senserva, at least one CVE is in the CISA KEV catalog (actively exploited). Max CVSS 8.8.
Per Mondoo, the fix for CVE-2026-45583 RCE is NOT included in the SU and requires separate mitigation steps. Parallel updates released for Exchange 2019 CU14/CU15 (KB5094140) and Exchange 2016 CU23 (KB5094144) via ESU. Exchange Online is not affected.
Active Exploitation Requires Priority Deployment
Per Senserva, this is a deploy-first update due to active exploitation. CVE-2026-42897 targets OWA, the most internet-exposed Exchange component. Unpatched on-premises Exchange servers remain a top target for nation-state and ransomware groups. Superseded by KB5103212 (July SU8).
Exchange Server SE, 2019, and 2016
Exchange Server SE RTM. Exchange 2019 CU14/CU15 and 2016 CU23 via ESU. Install from elevated prompt. Run HealthChecker after installation. Follow separate CVE-2026-45583 mitigation instructions.
Response
Response status: No response
Patch available: No
Workaround available: No