Pandorex
Security

Exchange KB5121608 Fixes Eight CVEs — and Ships With Two Known Hybrid Issues

Published Pandorex Redaktion·4 min read
—

Summary: Microsoft has released KB5121608 for Exchange Server Subscription Edition. It fixes eight security vulnerabilities, including the CVE-2026-55007 RCE, and moves Exchange SE to build 15.2.2562.49. Microsoft also documents two new known issues that are particularly relevant to hybrid deployments.

KB5121608 addresses CVE-2026-55007, CVE-2026-69355, CVE-2026-69356, CVE-2026-69361, CVE-2026-69375, CVE-2026-69378, CVE-2026-69382 and CVE-2026-69641. The most important technical issue is CVE-2026-55007: a double-free vulnerability that can let an unauthorized attacker execute code over the network. Microsoft rates it CVSS 8.1.

Two known side effects

After installation, published .ics calendars can return HTTP 500 to calendar applications. Free/busy lookups for delegated mailboxes can also fail in hybrid environments when the deployment uses only the Microsoft Graph-based availability path. That is notable because the same update fixes an older Graph free/busy bug that shifted busy intervals according to the requester's timezone.

Microsoft recommends running the Exchange Server Health Checker after installation. Its official build table lists Exchange SE build 15.2.2562.49 for September 8, 2026. Exchange 2019 CU14/CU15 and Exchange 2016 CU23 also receive corresponding September security builds.

Microsoft's own update label is inconsistent

The support page contains a small but avoidable operational ambiguity: the download section calls the package “RTM SU9”, while the hash and file-information sections on the same page call it “SU10”. Microsoft's build table avoids that numbering and labels the release simply “Sep26SU”.

Pandorex Analysis: For rollout records, KB5121608 plus build 15.2.2562.49 is therefore a clearer identifier than the SU9/SU10 label. The security fixes justify prompt deployment, but teams using hybrid availability or published calendars should explicitly test the two documented regressions before broad rollout.

Sources and references

Sources used for the facts and context in this article.

  1. Microsoft Support, 08.09.2026: Exchange Server SE Security Update KB5121608support.microsoft.com
  2. Microsoft Learn, geprüft am 09.09.2026: Exchange Server build numbers and release dateslearn.microsoft.com
  3. Microsoft Support, geprüft am 09.09.2026: Hybrid free/busy through Microsoft Graph incorrectly shifts busy timessupport.microsoft.com
  4. Microsoft Security Response Center, 08.09.2026: CVE-2026-55007msrc.microsoft.com

How Pandorex researches and corrects articles

Comments

Sign in to write a comment.

Swipe up
Next Article

Microsoft Patch Tuesday: Two Exploited Windows Flaws Matter More Than the Record Count

Security