KB5094140 Delivers ESU Security Patches for Exchange Server 2019
June 2026 security update for Exchange Server 2019 CU14 and CU15 via Extended Security Updates. Patches the same 8 CVEs as KB5094139 (Exchange SE) including CVE-2026-42897 OWA spoofing and CVE-2026-45583 RCE (separate mitigation required).

On this page
Key takeaways
- Same 8 CVEs as KB5094139 (Exchange SE SU7). Max CVSS 8.8.
- Requires ESU Period 2 eligibility for Exchange 2019.
- At least one CVE actively exploited (CISA KEV).
- CVE-2026-45583 RCE requires separate mitigation.
KB5094140 delivers June 2026 security patches for Exchange Server 2019 CU14/CU15 via Extended Security Updates. It patches the same 8 CVEs as Exchange SE SU7, including actively exploited OWA spoofing.
ESU security update for Exchange 2019 patches 8 CVEs including exploited OWA flaw.
Exchange 2019 ESU. Same 8 CVEs as Exchange SE. CVSS 8.8. Actively exploited. Requires ESU Period 2.
KB5094140 Delivers ESU Patches for Exchange 2019 CU14/CU15
Microsoft released KB5094140 on June 9, 2026, a security update for Exchange Server 2019 CU14 and CU15 delivered through Extended Security Updates (ESU) Period 2. Per the Exchange Server release pattern, it patches the same 8 CVEs as KB5094139 (Exchange SE SU7): CVE-2026-42897 (OWA spoofing), CVE-2026-45583 (RCE requiring separate action), and six additional spoofing, info disclosure, and EoP flaws.
Per Windows Forum, Exchange Server 2019 is now in Extended Security Updates only. Organizations need ESU Period 2 eligibility to receive these patches. Per Senserva, at least one CVE is in the CISA KEV catalog (actively exploited). Max CVSS 8.8.
ESU Required for Exchange 2019 Patching
Exchange 2019 reached end of mainstream support. Per Microsoft, ESU-only updates are available for CU14 and CU15. Organizations still running Exchange 2019 on-premises should plan migration to Exchange SE or Exchange Online.
Exchange 2019 CU14/CU15 with ESU
Exchange Server 2019 CU14 and CU15 with ESU Period 2 eligibility. Install from elevated prompt. Run HealthChecker after installation. Same CVE-2026-45583 separate mitigation applies.
Response
Response status: No response
Patch available: No
Workaround available: No
FAQ
What does KB5094140 fix?
Same 8 CVEs as Exchange SE SU7 (KB5094139): OWA spoofing, RCE, info disclosure, EoP. Max CVSS 8.8. At least one actively exploited.
Do I need ESU to install this?
Exchange 2019 is in Extended Security Updates only. You need ESU Period 2 eligibility to receive patches. Plan migration to Exchange SE or Exchange Online.
Sources
Microsoft · Jun 9, 2026 · Primary source
Claims supported
- Exchange 2019 CU14/CU15
- 8 CVEs