KB5094139 Addresses 8 Exchange Server CVEs; One RCE Needs Separate Mitigation
Install the current superseding Exchange Server update, verify the build with Health Checker, and handle CVE-2026-45583 separately; KB5094139 alone does not fix it.

On this page
Microsoft’s June 2026 Exchange Server SE update addresses eight listed vulnerabilities, including KEV-listed CVE-2026-42897, but it does not contain the fix for CVE-2026-45583.
Administrators should deploy the latest superseding Exchange Server update, verify the installed build, and follow Microsoft’s separate mitigation guidance for CVE-2026-45583.
KB5094139 addresses eight listed Exchange Server CVEs, but CVE-2026-45583 requires separate mitigation.
Install the latest Exchange Server update, prioritize KEV-listed CVE-2026-42897, and treat CVE-2026-45583 separately.
Affected & context
Microsoft released KB5094139 for Exchange Server Subscription Edition on June 9, 2026. The update lists eight resolved CVEs, while Microsoft states that the fix for CVE-2026-45583 is not included.
CISA lists CVE-2026-42897 in the Known Exploited Vulnerabilities catalog. Administrators must not assume KB5094139 also resolves CVE-2026-45583.
Organizations running Exchange Server Subscription Edition, and administrators still validating remediation for CVE-2026-45583.
KB5094139 lists eight Exchange Server CVEs
Microsoft released KB5094139 on June 9, 2026 for Exchange Server Subscription Edition RTM. The official support article lists eight resolved CVEs, including CVE-2026-42897, together with spoofing, information-disclosure, elevation-of-privilege, denial-of-service, cross-site-scripting, and remote-code-execution issues.
Microsoft explicitly states that the fix for CVE-2026-45583 is not included in KB5094139. Administrators must follow the separate instructions in Microsoft’s CVE advisory and should not treat installation of this update as remediation for that vulnerability.
Prioritize KEV-listed CVE-2026-42897
CISA’s Known Exploited Vulnerabilities catalog identifies CVE-2026-42897 as exploited in the wild. This supports urgent remediation for that specific Exchange OWA vulnerability; it does not mean that all eight CVEs listed in KB5094139 are known to be exploited. Microsoft’s later KB5103212 supersedes this June update.
Exchange Server administrators should deploy the latest update
Organizations running Exchange Server Subscription Edition should install the latest applicable superseding update from an elevated prompt, run Microsoft’s Health Checker afterward, and follow the separate CVE-2026-45583 mitigation guidance. Exchange Online is not affected by this on-premises servicing path.
Response
Response status: No response
Patch available: No
Workaround available: No
Sources
Microsoft · Primary source
CISA · Primary source
Microsoft · Primary source
Reader feedback
Written reviews
Loading reviews…