Microsoft released KB5121611, the September security update for Exchange Server 2016 CU23, addressing seven vulnerabilities: CVE-2026-69355, CVE-2026-69356, CVE-2026-69361, CVE-2026-69375, CVE-2026-69378, CVE-2026-69382, and CVE-2026-69641. A security advisory from Gambia’s national CSIRT characterized the Exchange Server issue as a pre-authentication remote-code-execution risk.
The update also fixes a hybrid-deployment issue that caused wrapper messages to appear in shared mailboxes following the June 2026 security update. Microsoft cautioned that published calendar .ics files may return HTTP 500 errors after installation; Exchange Server 2016 and 2019 are out of support, with updates available only to organizations in the Period 2 Extended Security Update program through October 2026, and organizations should migrate to Exchange Server Subscription Edition.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
Microsoft released Exchange Server 2016 Cumulative Update 23 Security Update 25 (KB5121611), addressing seven Exchange Server vulnerabilities: CVE-2026-69355, CVE-2026-69356, CVE-2026-69361, CVE-2026-69375, CVE-2026-69378, CVE-2026-69382, and CVE-2026-69641. The update also fixed a hybrid-environment shared-mailbox wrapper-message issue introduced after the June 2026 Security Update.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
gmcsirt.gm
Open sourcesupport.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.