Microsoft blames AI bug backlog for delayed Exchange SE update

Microsoft blames AI bug backlog for delayed Exchange SE update

Microsoft's Exchange team has told customers it cannot say when Exchange Server Subscription Edition (SE) will get its first Cumulative Update, CU1, blaming the delay on extra work generated by AI-powered vulnerability detection tools. The explanation came last Thursday in a blog post titled "Where is Exchange SE CU1 anyway?", written to address customer questions about the timeline. CU1 was originally promised by the end of the first half of 2026, then pushed to the second half of that year, and now carries no new target date at all.

Cumulative Updates for Exchange normally bundle bug fixes with new features or the removal of deprecated code and ship once or twice a year. Microsoft said unnamed "various Microsoft execs" have described the company as leveraging a variety of AI tools to help find vulnerabilities in its products, and that the development team is now working through the resulting reports monthly: validating that flagged issues are real security problems, reproducing them, fixing them, testing for regressions after each fix, and releasing the updates.

Microsoft also pointed to a broader commitment to "prioritize security above all else," a stance it adopted after the Exchange breach involving suspected Chinese operatives, which drew criticism from U.S. government officials. To avoid burdening administrators with two major releases close together, the Exchange team said it does not want CU1 to land right before or after a security update, since that would "create double the update work for many organization administrators." Instead, the team said it is rolling its monthly security payload into an internal CU1 build and plans to ship CU1 once it reaches "a reasonable stable point" and has a month without a pressing security payload to include. The team summed up its position bluntly: CU1 is coming, but there is no date to give, and it has not been forgotten.

Key facts

  • Exchange SE's first Cumulative Update, CU1, has no release date after slipping from the end of H1 2026 to H2 2026.
  • Microsoft attributes the delay to extra validation, reproduction, fixing and regression-testing work generated by AI-powered vulnerability-detection tools.
  • The Exchange team is now releasing updates monthly instead of the usual one or two Cumulative Updates a year.
  • Microsoft says it wants to avoid shipping CU1 alongside a security update, since doing so would double the update work for administrators.
  • The security-first stance traces back to the Exchange breach involving suspected Chinese operatives, which drew criticism from U.S. officials.

Why it matters

It is a concrete, named example of AI tooling creating real operational cost rather than only productivity gains: Microsoft's own vulnerability-detection AI is generating a stream of findings that has to be validated, reproduced, fixed and regression-tested by humans, and that workload is large enough to indefinitely delay a promised enterprise release with no new date offered.

Who it affects

Exchange Server Subscription Edition administrators and the organizations relying on it are the direct audience, since they were expecting CU1 by mid-2026 and now have no timeline. More broadly, it is a data point for any team evaluating AI-assisted vulnerability scanning about the downstream triage load such tools can create.

How to use it

There is no CU1 to install yet. Microsoft's own guidance is to keep applying the monthly security updates it is already shipping rather than wait for a bundled Cumulative Update, since the team says it will not release CU1 alongside a security update to avoid doubling administrators' work.

How solid is it

The account comes directly from Microsoft's own Exchange team blog post, quoted extensively by The Register rather than paraphrased second-hand. It is a single-source company statement, however, and does not name which executives made the underlying claims about AI tool usage or give any figure for how many vulnerabilities the tools have surfaced.

Risks and caveats

Microsoft has not committed to any new date, only that CU1 "is coming." The article does not quantify the AI-generated backlog, name the AI tools involved, or state that the breach directly caused the shift to AI-assisted scanning, only that the security-first stance followed it. Whether the monthly cadence is sustainable, or CU1 will keep slipping, is not addressed in the source.

“In short: Exchange SE CU1 is coming; we do not have a date to give you. But we did not forget about it.”

— the Exchange team, in Microsoft's blog post