A blog post published on August 13th by Microsoft’s Exchange Team outlines a further delay in the release of Exchange SE Cumulative Update 1 (CU1). The update was initially expected in the first half of 2026, later changed to the second half of calendar year 2026, and this latest information emphasizes that it is coming, just on a longer timeline than originally predicted.
The blog post frames the continued delay as a shift in the timeline, not a crisis, but it is the second such pushback in under a year, drawing questions from customers. The real story behind this is not the question of precisely when the update will be released, but the stated reason for the delays: the ongoing advancement of AI-assisted vulnerability discovery.
How AI Discovery Creates a Bottleneck
The challenge presented with the use of AI-assisted vulnerability discovery is an issue of volume and speed. Working at machine speed without the need for breaks or hesitations, AI tools are able to surface far more potential issues than human triage can possibly absorb. Every problem flagged by AI is a finding that requires validation, reproduction, fixing, and regression testing—all processes that take time and attention. “This is concerning,” says John Strand, Owner of Black Hills Information Security, Inc. “If we have so many vulnerabilities coming in that it’s actually delaying cumulative updates and patches from vendors, that’s a sign the system is starting to seize up a little bit.”
Even as development stalls on CU1, there have been monthly security releases for Exchange Server, and this pace of security updates is planned to continue as the Exchange Team works on security efforts. The Exchange Team wishes to maintain the security of the product while CU1 development is ongoing with an uncertain release date.
The Security-First Mandate
There are a number of reasons that Exchange’s security is being so heavily focused on at this time and in this security landscape. The massive wave of Exchange Server attacks by state-linked actors in 2021 was not forgotten quickly; rather, it raised alarms and triggered lasting scrutiny.
In the wake of those attacks, and with rising geopolitical tensions laying the perfect groundwork for state-sponsored cyberthreats, the US government placed pressure on Microsoft to improve security posture and capabilities, pushing the company to establish a culture and strategy of “prioritizing security above all else.” This governmental mandate is now directly colliding with vulnerability discovery capabilities at AI scale, forcing the delay in CU1’s release.
The Moving Target
The main issue outlined by the Exchange Team regarding this update is that the scope of the project repeatedly grows larger the longer they work on it. The development and release of CU1 is stuttering because each newly validated fix gets folded into the internal build, continually expanding the size of the update and the amount of work that needs to be done in order to complete it. The stability of the changes also keeps resetting as the scope of the project grows to include everything since the RTM.
In concert with the delay of CU1, the timeline for Exchange Server SE CU2 has also been pushed back. Currently somewhat tentatively slated for the first half of calendar year 2027, this update will enable continued Exchange Server SE development and end the product’s compatibility with unsupported Exchange versions (2013, 2016, and 2019). Both CU1 and CU2 lack official release dates as development continues.
A Preview for AI-Augmented Security Programs
The delays in CU1’s development and release are not an anomaly that will only affect Exchange, but a company-wide problem resulting from AI-enhanced security technologies. Detection capabilities are scaling faster than remediation capacity, presenting a shared industry risk that all organizations relying on AI for vulnerability discovery should be concerned with mitigating. Vendors who lean into AI-assisted scanning will continue to inherit the same triage bottleneck.
What Security Leaders Should Do
Given that the Exchange Team does not have a release date for CU1, it is important for defenders to treat monthly security updates as the operational patch baseline. Security leaders are encouraged to build test environments and change-approval processes independent of vendor calendars rather than being beholden to Microsoft’s schedule. Vendor trust comes not from strict adherence to specific release dates, but from transparency concerning the ongoing process. The Exchange Team providing this update and continuing monthly security releases is a sign of the company doing its best to maintain security and customer trust in an uncertain time.