KB5094144 delivers June 2026 ESU security patches for Exchange Server 2016 CU23. Same 8 CVEs as Exchange SE SU7 including actively exploited OWA spoofing. Exchange 2016 is deep in extended support.
Key takeaways
- Same 8 CVEs as Exchange SE SU7. CVSS 8.8. Actively exploited.
- Exchange 2016 is three years past end of extended support.
- Requires ESU Period 2 eligibility.
- Plan migration to Exchange SE or Exchange Online immediately.
KB5094144 Patches 8 CVEs in Exchange 2016 CU23 via ESU
Microsoft released KB5094144 on June 9, 2026, a security update for Exchange Server 2016 CU23 via Extended Security Updates Period 2. It patches the same 8 CVEs as Exchange SE SU7 (KB5094139) and Exchange 2019 (KB5094140): CVE-2026-42897 (OWA spoofing), CVE-2026-45583 (RCE requiring separate action), and six additional flaws.
Exchange 2016 reached end of mainstream support in October 2020 and end of extended support in October 2025. Per Windows Forum, organizations still running Exchange 2016 need ESU Period 2 eligibility and should plan migration to Exchange SE or Exchange Online.
Exchange 2016 Is Deep in Extended Support
Exchange 2016 is now three years past end of extended support. Each month of continued operation increases risk. Per Microsoft, ESU patches are a bridge to migration, not a long-term solution. At least one CVE is actively exploited (CISA KEV).
Exchange 2016 CU23 with ESU
Exchange Server 2016 CU23 with ESU Period 2 eligibility only. Install from elevated prompt. Run HealthChecker. Follow CVE-2026-45583 separate mitigation.
FAQ
What does KB5094144 fix?
Same 8 CVEs as Exchange SE SU7 (KB5094139). Max CVSS 8.8. At least one actively exploited.
Is Exchange 2016 still supported?
Exchange 2016 reached end of extended support in October 2025. ESU Period 2 provides security-only patches as a bridge to migration.






