5 of 100 stories tagged “Security Updates”
More 129

KB5094140 Delivers ESU Security Patches for Exchange Server 2019
KB5094140 is the June 2026 ESU security update for Exchange 2019 CU14/CU15 patching 8 CVEs including actively exploited OWA spoofing. Same CVEs as Exchange SE SU7 (KB5094139). Requires ESU Period 2 eligibility.

KB5094144 Patches Exchange Server 2016 CU23 via ESU
KB5094144 is the June 2026 ESU update for Exchange 2016 CU23 patching 8 CVEs including actively exploited OWA spoofing. Exchange 2016 is deep in extended support. Requires ESU Period 2.

KB5094139 Patches 8 CVEs in Exchange Server SE Including Exploited Flaw
KB5094139 patches 8 CVEs in Exchange Server SE including RCE, spoofing, info disclosure, and EoP. At least one actively exploited. Max CVSS 8.8. Also available for Exchange 2019 and 2016 via ESU.

KB5090408 Patches CVSS 8.8 RCE in SQL Server 2019 GDR
KB5090408 patches CVE-2026-40370 (CVSS 8.8 RCE via path manipulation) in SQL Server 2019 GDR. Build 15.0.2170.1. For instances on the GDR servicing branch (no CUs). MSDASQL Msg 7416 breaking change. Superseded by KB5102336.

KB5090407 Patches CVSS 8.8 Path Manipulation RCE in SQL Server 2019 CU32
KB5090407 patches CVE-2026-40370 (CVSS 8.8 RCE via path manipulation) in SQL Server 2019 CU32. Build 15.0.4470.1. MSDASQL linked server queries with @provstr fail with Msg 7416 after installation.

