SAN FRANCISCO — Microsoft has no release date for Exchange Server SE Cumulative Update 1. The company confirmed the delay in a post on the Microsoft Community Hub, citing a sustained pace of AI-driven vulnerability discovery that keeps generating security fixes faster than the team can clear the backlog.

The Exchange Server engineering team has shipped security updates in May, June, July and August 2026—four consecutive months of patches. The team said it is prioritizing security above all else, and that pace shows no sign of slowing.

The root cause is a company-wide initiative. Multiple Microsoft executives have publicly described how the company is using AI tools to surface vulnerabilities across its product portfolio. The Exchange Server team is one of many groups now working through a queue that includes validating whether reported issues are real security problems, reproducing them, building fixes and testing for regressions before each monthly release.

The mechanics of why that backlog blocks CU1 are straightforward. A Cumulative Update must be all-inclusive: every security fix shipped since the original release to manufacturing must be rolled into the CU. If Microsoft releases CU1 and then immediately ships another security update on top of it, enterprise administrators face two major update operations in rapid succession instead of one. The team said it does not want to create double the update work for organization administrators.

There is also an internal testing burden. Running two major releases simultaneously—a Cumulative Update and a Security Update—requires parallel validation tracks. The engineering team said ensuring high quality across both without anything falling through the cracks would be very challenging given the volume of fixes in play.

Microsoft's approach is to keep rolling the monthly security payload into the internal CU1 build and release the update when the team reaches a stable point with a month free of pressing security fixes. That threshold has not been met yet.

The delay pushed past two earlier public commitments. Microsoft originally said CU1 would arrive by the end of the first half of calendar year 2026. It later revised that to the second half of 2026. The team acknowledged the slip without providing a revised deadline, saying only that it did not forget about CU1.

For enterprise IT teams managing on-premises Exchange Server SE deployments, Microsoft's advice is to complete the upgrade to Exchange Server SE if they have not done so and to apply every monthly security update as released. The company is not asking customers to wait for CU1 before upgrading—it is explicitly telling them to keep moving and stay current on security patches in the interim.

The business context matters for large organizations evaluating on-premises email infrastructure. Exchange Server SE is Microsoft's current-generation on-premises mail server, positioned for organizations that cannot or will not move fully to Exchange Online. CU1 typically carries performance improvements, bug fixes and configuration changes that organizations need before they can fully deploy or stabilize the platform. An indefinite delay on CU1 means those fixes remain unavailable outside the monthly security update track, which does not carry the full feature and stability payload a CU delivers.

Microsoft's use of AI to accelerate vulnerability discovery is producing real output—four months of consecutive patches is evidence of that—but it is also creating a secondary problem: the fix rate is outrunning the team's ability to bundle and ship a clean major release. That tension is not unique to Exchange; it is a predictable consequence of deploying automated security scanning at scale across a large, legacy-adjacent codebase. The Exchange team is absorbing that cost visibly, in the form of a CU that keeps slipping.