Summary: Microsoft has released KB5121608 for Exchange Server Subscription Edition. It fixes eight security vulnerabilities, including the CVE-2026-55007 RCE, and moves Exchange SE to build 15.2.2562.49. Microsoft also documents two new known issues that are particularly relevant to hybrid deployments.
KB5121608 addresses CVE-2026-55007, CVE-2026-69355, CVE-2026-69356, CVE-2026-69361, CVE-2026-69375, CVE-2026-69378, CVE-2026-69382 and CVE-2026-69641. The most important technical issue is CVE-2026-55007: a double-free vulnerability that can let an unauthorized attacker execute code over the network. Microsoft rates it CVSS 8.1.
Two known side effects
After installation, published .ics calendars can return HTTP 500 to calendar applications. Free/busy lookups for delegated mailboxes can also fail in hybrid environments when the deployment uses only the Microsoft Graph-based availability path. That is notable because the same update fixes an older Graph free/busy bug that shifted busy intervals according to the requester's timezone.
Microsoft recommends running the Exchange Server Health Checker after installation. Its official build table lists Exchange SE build 15.2.2562.49 for September 8, 2026. Exchange 2019 CU14/CU15 and Exchange 2016 CU23 also receive corresponding September security builds.
Microsoft's own update label is inconsistent
The support page contains a small but avoidable operational ambiguity: the download section calls the package “RTM SU9”, while the hash and file-information sections on the same page call it “SU10”. Microsoft's build table avoids that numbering and labels the release simply “Sep26SU”.
Pandorex Analysis: For rollout records, KB5121608 plus build 15.2.2562.49 is therefore a clearer identifier than the SU9/SU10 label. The security fixes justify prompt deployment, but teams using hybrid availability or published calendars should explicitly test the two documented regressions before broad rollout.