Security advisory
Microsoft ExchangeMediumActiveUpdated Aug 25, 2026

Microsoft Delays Exchange SE CU1 Again, Cites AI-Found Security Bugs

Exchange SE CU1 has slipped past two announced windows as Microsoft's security team works through a growing backlog of AI-flagged findings.

Emanuel De AlmeidaAug 25, 2026, 9:24 PM7 min read
Severity
Medium
Status
Active
Entity
Microsoft
Confirmed by
Microsoft Exchange team blog post

Microsoft has delayed the release of Exchange Server Subscription Edition (SE) Cumulative Update 1, telling customers in a blog post published last Thursday that AI-assisted code scanning has surfaced more security findings than its Exchange engineers can validate and fix on the previous schedule. The post, titled "Where is Exchange SE CU1 anyway?", was Microsoft's response to repeated customer questions about the missing update, according to The Register.

The delay matters because Exchange administrators who scheduled testing and deployment windows around Microsoft's earlier CU1 targets now have no committed date to plan against, and Microsoft's own account suggests AI-assisted vulnerability discovery is outpacing its capacity to triage and remediate findings across product teams.

Key takeaways

  • Microsoft delayed Exchange SE CU1 for the second time, with no new release date given.
  • Microsoft says AI-assisted code scanning is producing more security findings than engineers can validate and fix on schedule.
  • CU1 originally targeted the end of the first half of 2026, then slipped to the second half of 2026.
  • Monthly Exchange SE security updates continue on schedule and are unaffected by the CU1 delay.
  • An independent analyst recommends enterprises treat CU1 as a trigger-based project rather than a scheduled release.

Affected

Vendors
Microsoft
Products
Exchange Server Subscription Edition (SE)Exchange SE Cumulative Update 1 (CU1)
Geography
Global
Industry
Enterprise IT

What did Microsoft say about the Exchange SE CU1 delay?

Exchange Server Subscription Edition (SE) Cumulative Update 1, commonly called CU1, is the first major consolidated update for Microsoft's current on-premises Exchange release, and it remains unavailable with no committed ship date. Microsoft's Exchange team addressed the delay directly in a blog post titled "Where is Exchange SE CU1 anyway?", published last Thursday, after fielding repeated customer questions about the missing release, The Register reported on 2026-08-17.

According to Computerworld's account of the post, Microsoft said its engineers are racing to validate a growing volume of security findings surfaced through AI-assisted code scanning before CU1 can ship. The company noted that "various Microsoft execs" have publicly described the firm's use of AI tools to hunt for vulnerabilities across its product lines, and that teams including Exchange Server are now working through the resulting reports.

  • CU1 has now missed two announced release windows: end of H1 2026 and later all of H2 2026.
  • Microsoft has not stated a new target date for CU1's release.

Why is AI-assisted scanning slowing down a security release?

AI-assisted code scanning is meant to find vulnerabilities faster than manual review, but Microsoft's own account shows the opposite effect on Exchange's release cadence: more findings mean more validation work before any fix can ship. Per Microsoft's post as relayed by Computerworld on 2026-08-17, each reported issue must be confirmed as a genuine security problem, reproduced, fixed, tested for regressions, and released, a pipeline that scales with headcount and process, not with how fast a scanner produces alerts.

This creates a bottleneck that is downstream of the AI tooling itself: the scanning step got faster, but the human validation and regression-testing steps did not. Microsoft continues to ship monthly Exchange SE security updates on schedule, so the delay is specific to the larger, more disruptive CU1 package rather than to routine patching.

Who is affected by the Exchange SE CU1 delay?

Organizations running Exchange Server Subscription Edition on-premises are the ones waiting on CU1, since a Cumulative Update consolidates recent bug fixes and security updates while potentially adding new features, architectural changes, or removing deprecated components. Enterprises that hold off on other changes until a CU lands, a common practice given the scope of testing a CU requires, are now in an indefinite holding pattern.

  • IT teams that paused infrastructure changes pending CU1's arrival
  • Admins who scheduled testing windows around Microsoft's earlier H1 or H2 2026 targets
  • MSPs managing multiple Exchange SE customer environments with differing patch policies

How should enterprises plan without a CU1 date?

Manoj Chandra Jha, principal analyst at Nord-IQ Research, told Computerworld that the second delay and the absence of any committed shipping month should prompt enterprises to change how they plan around CU1. Jha recommended treating the monthly security update cadence as the operational patch baseline, and treating CU1 itself as a discrete, trigger-based project rather than a scheduled release, until Microsoft provides a firmer signal.

Jha also advised against standing still while waiting for a date: CIOs can separate CU1 readiness from Microsoft's release calendar by maintaining a test environment, inventorying and pre-validating authentication, APIs and management tools, and setting up a fast-track change-approval process that activates as soon as Microsoft announces the update.

  • Analyst guidance: keep applying monthly security updates as the baseline, don't wait on CU1 for those.
  • Recommended prep work: test environment, pre-validated auth/API/management tooling, fast-track change approval.

Is Exchange the only Microsoft-adjacent team hitting this AI bottleneck?

Exchange is not the only part of Microsoft's ecosystem confronting a mismatch between AI-generated output and the human capacity to review it. GitHub, which popularized AI-assisted coding through Copilot, considered letting repository maintainers restrict or disable pull requests in February after maintainers warned that a surge of low-quality, often AI-generated submissions was overwhelming open-source projects, Computerworld reported.

GitHub later shipped Stacked PRs in April to help developers break larger AI-assisted changes into smaller, more reviewable units. AWS added release management features to its DevOps Agent in June to help teams validate AI-generated code before deployment, and GitHub separately said in May it had seen a sharp rise in low-quality security submissions to its bug bounty program, prompting it to scale back rewards for low-impact reports and ask researchers to focus on meaningful risks.

What happens next for Exchange SE CU1?

Microsoft has given no timeline for CU1 and, per its own account, the update depends on how quickly the Exchange team can clear its backlog of AI-flagged findings through validation, reproduction, fixing and regression testing. Watch for a follow-up post on the Exchange team blog once Microsoft has a firmer date to share, and for whether other Microsoft product teams cite similar AI-driven review bottlenecks in their own release notes.

Planning note

Exchange administrators should not build deployment plans around an assumed CU1 date; instead, treat monthly security updates as the current baseline and keep a test environment ready to move quickly once Microsoft announces a release.

Timeline

CU1 first targeted for H1 2026Microsoft initially indicated Exchange SE CU1 would arrive by the end of the first half of 2026.
Target revised to H2 2026Microsoft pushed its expected CU1 release window back to the second half of 2026.
Aug 13, 2026
Microsoft publishes "Where is Exchange SE CU1 anyway?"Microsoft's Exchange team addressed customer questions about the missing update and cited AI-assisted vulnerability discovery as the reason for further delay.

Impact & actions

Exchange administrators lose a firm date to plan testing and deployment windows for CU1, and must treat monthly security updates as the only reliable patch cadence for now.

Security: Microsoft says the delay stems from a growing backlog of security findings surfaced by AI-assisted code scanning that engineers must validate, reproduce and fix before shipping, though monthly Exchange SE security updates continue unaffected.

Recommended actions · Medium urgency

  1. 1Continue applying Exchange SE monthly security updates as the operational patch baseline rather than waiting for CU1
  2. 2Maintain a test environment and pre-validate authentication, API and management tooling ahead of an eventual CU1 release
  3. 3Establish a fast-track change-approval process that can be activated once Microsoft announces a firm CU1 date
  4. 4Track Microsoft's Exchange team blog for the next update rather than planning around the previous H1/H2 2026 targets

Technical details

Mitigations

  • Apply Exchange SE monthly security updates on schedule instead of waiting for CU1

Response

Vendor

Microsoft's Exchange team wrote that engineers are "working through reported issues, which includes validation that they are real security issues, reproducing, fixing, testing for regressions / issues after fixes are deployed and releasing updates monthly." The added workload appears to stem from a growing volume of security findings surfaced through AI-assisted code scanning, though Microsoft's statement itself did not explicitly frame it that way.

Customer guidance

Microsoft has told customers it cannot yet give a new CU1 date and is directing them to keep applying the monthly Exchange SE security updates, which remain on schedule.

Updates

Aug 17, 2026Microsoft confirms second CU1 delay

Microsoft's Exchange team published a blog post acknowledging that Exchange SE CU1 has slipped past its second target window, citing AI-assisted security findings, with no new date given.

FAQ

What is Exchange SE CU1 and why is it delayed?

CU1 is the first Cumulative Update for Exchange Server Subscription Edition, consolidating fixes, features and architectural changes. Microsoft delayed it a second time because engineers must validate a growing backlog of security findings surfaced by AI-assisted code scanning before release.

When will Exchange SE CU1 be released?

Microsoft has not given a new release date. CU1 originally targeted the end of the first half of 2026, then slipped to the second half of 2026, and now has no committed window.

Are Exchange SE monthly security updates affected by the delay?

No. Microsoft says its monthly Exchange SE security updates continue on their normal schedule and are separate from the CU1 delay.

How should enterprises plan without a CU1 date?

An analyst quoted by Computerworld recommends treating monthly security updates as the patch baseline and CU1 as a trigger-based project, maintaining a test environment and pre-validating authentication, API and management tools so deployment can start quickly once Microsoft announces a date.

Is Microsoft's Exchange team the only group affected by AI-generated review backlogs?

No. GitHub, AWS and CodeRabbit have all introduced features to help teams manage growing volumes of AI-generated code and security submissions, according to Computerworld's reporting.

The bottom line

Microsoft has delayed Exchange SE CU1 for a second time, saying AI-assisted code scanning has produced more security findings than engineers can validate and fix on schedule, and it has not set a new release date.

What to do

Keep applying Exchange SE monthly security updates and prepare a test environment now so CU1 can be validated quickly once a release date is announced.

Reader reviews

Rate this articleBe the first to rate
No written reviews yetRate the article above, or be the first to share your experience.

Related articles