Microsoft Says AI Bug-Finders Are Delaying a Key Exchange Server Update, With No Release Date in Sight
The company's own AI-powered security tools are generating so many potential flaws to investigate that the team can't find a quiet month to ship the update safely.

Key points
- Microsoft has delayed Exchange Server SE Cumulative Update 1 (CU1), a major bundled software update, with no firm release date given as of June 2026.
- The company says AI-powered tools that scan its own software for security flaws are producing a steady stream of issues that must be fixed before the update ships.
- Microsoft originally promised CU1 by mid-2026, then pushed the target to "second half of 2026", and has now stopped giving a date entirely.
- The Exchange team says releasing CU1 alongside a separate security patch in the same month would create double the update work for the IT administrators who manage corporate email servers.
Microsoft's corporate email server software, Exchange Server SE (SE stands for Subscription Edition, meaning companies pay a recurring fee rather than buying it outright), is missing an update that was promised months ago. A Cumulative Update, or CU, is a single package that rolls up every recent bug fix plus new features into one installable release. Microsoft publishes these once or twice a year, and many system administrators, the IT staff who keep company networks running, prefer waiting for a CU over applying individual patches one by one.
The problem, as The Register AI first reported, is that the CU keeps getting pushed back.
What is actually holding the update up?
AI tools built to find security flaws are finding them faster than the team can ship fixes cleanly. Microsoft has been rolling out artificial intelligence tools across its engineering teams to scan its own products for vulnerabilities, weaknesses in software that attackers could exploit. Those tools are working. They are also generating a constant queue of issues that must be verified, reproduced, patched and tested before they can be released.
The Exchange team posted an explanation on its official blog under the blunt title "Where is Exchange SE CU1 anyway?" The post says the team is "working through reported issues" and rolls new security fixes into its internal CU1 build every month. It plans to ship the CU only when it can find "a month without pressing security payload", meaning a month where no urgent security patch needs to go out at the same time.
The concern is practical. Pushing two major releases in one month, a security update and a CU, would force administrators to install both in quick succession. The team describes that as "double the update work" and warns that testing two large releases in parallel would be "very challenging."
Why does the security backlog keep growing?
Microsoft adopted a formal "security above all else" policy after suspected Chinese state hackers exploited flaws in Exchange to breach email accounts at US government agencies. That incident drew sharp criticism from the US government and put Exchange under intense scrutiny. The company then invested heavily in AI-assisted vulnerability scanning, and the Exchange team is now working through the results.
The post is candid about the gap between ambition and planning: nobody appears to have modelled what a steady flood of AI-generated bug reports would do to a team's release schedule.
| Target | Status |
|---|---|
| End of H1 2026 (original) | Missed |
| Second half of 2026 (revised) | No date given |
| Current commitment | "CU1 is coming" |
What does this mean for IT teams?
Administrators running Exchange SE should keep applying monthly security patches as they arrive. Those patches are still shipping on schedule. CU1 will deliver everything in one bundle eventually, but Microsoft will not say when. For now, the message from Redmond is simply: "We did not forget about it."
Organisations that chose Exchange SE partly because of its subscription-based update promise may want to factor the delay into their planning for the rest of the year.
Common questions
Is Exchange email itself broken or at risk right now?
No. Microsoft continues to ship monthly security fixes for Exchange SE. The delay affects only the larger bundled CU1 release, not the ongoing security patches.
Do ordinary email users need to do anything?
No action is needed from end users. The update affects server administrators, not the people who send and receive email on Exchange. Your IT team handles this.
Will AI tools keep causing delays like this in future updates?
Microsoft has not said. The team is adapting its release process as it learns how many issues AI scanning can surface, but it has offered no timeline or policy change to prevent the same situation recurring.



