2026年9月Exchange Server安全更新已发布

Exchange产品组已于2026年9月9日发布最新Exchange Server SU(安全更新),请大家及时测试并安装更新。

一、详细说明请看产品组博文:

Released: September 2026 Exchange Server Security Updates

二、要点总结如下:

1、根据KB描述,9月SU修复了以下8个CVE,其中CVSS基本分数最高达到了9.3属于重要级别

Description of the security update for Microsoft Exchange Server Subscription Edition RTM September 8, 2026 (KB5121608) | Microsoft Support

  1. CVE-2026-55007 - Microsoft Common Vulnerabilities and Exposures
  2. CVE-2026-69355 - Microsoft Common Vulnerabilities and Exposures
  3. CVE-2026-69356 - Microsoft Common Vulnerabilities and Exposures
  4. CVE-2026-69361 - Microsoft Common Vulnerabilities and Exposures
  5. CVE-2026-69375 - Microsoft Common Vulnerabilities and Exposures
  6. CVE-2026-69378 - Microsoft Common Vulnerabilities and Exposures
  7. CVE-2026-69382 - Microsoft Common Vulnerabilities and Exposures
  8. CVE-2026-69641 - Microsoft Common Vulnerabilities and Exposures

2、Exchange Server SE RTM SU10下载地址:

Download Security Update for Exchange Server SE RTM SU10 (KB5121608) from Official Microsoft Download Center

注意:Exchange 2016和2019因为已不受支持,除非注册了ESU v2(第二阶段扩展安全更新项目),否则无法下载最新SU,唯一获取和应用新SU的方法是升级Exchange Server。

3、本次更新修正了两个之前发现已知问题:

  1. Wrapper messages appear in shared mailbox in hybrid environments after installing the June 2026 Security Update
  2. Hybrid free/busy through Microsoft Graph incorrectly shifts busy times by requester timezone

4、然后多了两个已知问题:

  1. Published calendar (.ics) returns HTTP 500 for calendar applications
  2. Availability (free/busy) fails for delegated mailboxes in Exchange hybrid deployments using Graph API only

5、安装这个月SU同样不会自动移除在5月应用的CVE-2026-42897缓解措施,如果之前没有移除或撤销过需要:

A、如果是自动执行的缓解措施,请手动阻止应用相关EM(Exchange 紧急缓解服务)并删除之前创建的相关IIS规则,请看:

https://learn.microsoft.com/zh-cn/Exchange/plan-and-deploy/post-installation-tasks/security-best-practices/exchange-emergency-mitigation-service#rollback-procedures-for-released-mitigations

注意:针对CVE-2026-42897,阻止缓解命令用到的缓解ID是M2.1.0

B、如果之前使用的是EOMT(Exchange本地缓解工具)手动应用的缓解措施,请下载最新的EOMT执行撤销缓解操作,请看:

https://microsoft.github.io/CSS-Exchange/Security/EOMT/#roll-back-a-mitigation

6、安装完SU后,建议下载并执行最新Exchange Health Checker脚本进行最终检查:

https://microsoft.github.io/CSS-Exchange/Diagnostics/HealthChecker/

注意:脚本现在还会检测是否存在老旧、已弃用的旧版所遗留Exchange Server安全组,如Exchange Domain Servers 和 Exchange Enterprise Servers,这些组自Exchange 2007起已被弃用,不应继续使用,如报告中出现,建议及时删除,以免带来风险。

7、安装最新的SU是正常应用后续可能的EM的前提条件,否则2026年7月起将无法应用可能出现的新EM。

如果您有问题,欢迎留言或是到5DMail专属微信群来讨论!

分享到