Skip to content
anavem.com logoanavem.com logo
AdvisoryMedium priorityNewsExchange Server security update

KB5094139 Addresses 8 Exchange Server CVEs; One RCE Needs Separate Mitigation

Install the current superseding Exchange Server update, verify the build with Health Checker, and handle CVE-2026-45583 separately; KB5094139 alone does not fix it.

On this page

Microsoft’s June 2026 Exchange Server SE update addresses eight listed vulnerabilities, including KEV-listed CVE-2026-42897, but it does not contain the fix for CVE-2026-45583.

Administrators should deploy the latest superseding Exchange Server update, verify the installed build, and follow Microsoft’s separate mitigation guidance for CVE-2026-45583.

KB5094139 addresses eight listed Exchange Server CVEs, but CVE-2026-45583 requires separate mitigation.

Install the latest Exchange Server update, prioritize KEV-listed CVE-2026-42897, and treat CVE-2026-45583 separately.

Affected & context

Event summary

Microsoft released KB5094139 for Exchange Server Subscription Edition on June 9, 2026. The update lists eight resolved CVEs, while Microsoft states that the fix for CVE-2026-45583 is not included.

Why it matters

CISA lists CVE-2026-42897 in the Known Exploited Vulnerabilities catalog. Administrators must not assume KB5094139 also resolves CVE-2026-45583.

Who is affected

Organizations running Exchange Server Subscription Edition, and administrators still validating remediation for CVE-2026-45583.

KB5094139 lists eight Exchange Server CVEs

Microsoft released KB5094139 on June 9, 2026 for Exchange Server Subscription Edition RTM. The official support article lists eight resolved CVEs, including CVE-2026-42897, together with spoofing, information-disclosure, elevation-of-privilege, denial-of-service, cross-site-scripting, and remote-code-execution issues.

Microsoft explicitly states that the fix for CVE-2026-45583 is not included in KB5094139. Administrators must follow the separate instructions in Microsoft’s CVE advisory and should not treat installation of this update as remediation for that vulnerability.

Prioritize KEV-listed CVE-2026-42897

CISA’s Known Exploited Vulnerabilities catalog identifies CVE-2026-42897 as exploited in the wild. This supports urgent remediation for that specific Exchange OWA vulnerability; it does not mean that all eight CVEs listed in KB5094139 are known to be exploited. Microsoft’s later KB5103212 supersedes this June update.

Exchange Server administrators should deploy the latest update

Organizations running Exchange Server Subscription Edition should install the latest applicable superseding update from an elevated prompt, run Microsoft’s Health Checker afterward, and follow the separate CVE-2026-45583 mitigation guidance. Exchange Online is not affected by this on-premises servicing path.

Response

Response status: No response

Patch available: No

Workaround available: No

Sources

  1. Microsoft · Primary source

  2. CISA · Primary source

  3. Microsoft · Primary source

Reader feedback

Was this helpful?
Rate this articleRate

Written reviews

Loading reviews…