The Week at a Glance

  • 🔴 Exchange Server on-premises requires immediate patching: Microsoft released August 2026 security updates for Exchange Server on-premises (all supported versions), and organizations that delay face active exploit risk against a business-critical system; if you are on Exchange Server 2016 or 2019, you must also be enrolled in a paid Extended Security Update program to receive these fixes at all.
  • 🟡 Multiple remote code execution vulnerabilities patched across Office, Teams, PowerShell, and Windows: This month’s disclosures include vulnerabilities in Word, Teams (desktop, iOS, and Android), PowerShell, .NET, and Windows Server network drivers; your IT team should confirm patch status across all managed endpoints within the next two weeks.
  • 🟡 Exchange Server CU1 delay exposes a planning gap for on-premises customers: Microsoft has acknowledged that the first cumulative update for Exchange Server Subscription Edition will arrive later than originally committed, caused by AI-assisted security scanning that uncovered additional vulnerabilities; organizations planning infrastructure updates should revise their timelines.
  • 🟢 DLP and eDiscovery get meaningful enforcement upgrades: File quarantine for SharePoint and OneDrive DLP policies is in preview, and eDiscovery is gaining customer-managed encryption key support; compliance teams should begin evaluating both for regulated data environments.

Sources: Exchange Server Security Updates Blog · Microsoft Security Response Center · Exchange SE CU1 Update


Why This Week Matters

This week’s patch release is broad and consequential: vulnerabilities span the tools your employees use every day, from Word and Teams to the Windows infrastructure beneath them. Organizations still running Exchange Server on-premises carry the highest immediate risk, because they must take deliberate action to patch a system that sits at the center of business communication. The Exchange CU1 delay is a secondary signal worth noting: Microsoft’s own AI-assisted security review is finding more vulnerabilities than traditional processes did, which means the overall patch burden for on-premises infrastructure is likely to increase before it decreases.

Sources: Exchange Server Security Updates Blog · Exchange SE CU1 Update


Risk & Compliance

  • 🔴 August 2026 Exchange Server Security Updates: Unpatched Exchange Server is one of the most exploited attack surfaces in enterprise environments; organizations on Exchange 2016 or 2019 must also confirm active ESU program enrollment or they will not receive these patches at all, creating a direct compliance gap under HIPAA, SOC 2, and CMMC frameworks. Act this week.

  • 🔴 CVE-2026-40400 / CVE-2026-70337: Windows PowerShell Remote Code Execution: Remote code execution via PowerShell means an attacker who reaches an unpatched endpoint can run arbitrary commands with system-level access; confirm patch deployment status with your IT team immediately, as PowerShell is present on virtually every managed Windows device.

  • 🔴 CVE-2026-66807 / CVE-2026-63519 / CVE-2026-63513: Microsoft Office Graphics Remote Code Execution: Three separate Office vulnerabilities allow code execution through maliciously crafted documents, a common phishing delivery mechanism; organizations in regulated industries should treat unpatched Office installations as an open compliance risk under SOC 2 and CMMC.

  • 🔴 CVE-2026-56188: Windows Server Network Driver Remote Code Execution: A remotely exploitable flaw in the Windows Server network driver could allow attackers to compromise server infrastructure without user interaction; server patching should be prioritized alongside endpoint updates.

  • 🟡 CVE-2026-65768 / CVE-2026-65769 / CVE-2026-65767: Microsoft Teams Remote Code Execution and Spoofing: Vulnerabilities affecting Teams on desktop, iOS, and Android include remote code execution and a spoofing risk on Android; Teams updates are typically delivered automatically, but organizations managing mobile devices through Intune should verify that the corrected build versions are deployed.

  • 🟡 Microsoft Purview DLP File Quarantine for SharePoint and OneDrive: This preview feature automatically removes access to sensitive files that trigger a DLP policy, containing data exposure before it spreads; compliance and legal teams in healthcare, finance, and government should evaluate this capability now, as it directly supports HIPAA minimum-necessary and GDPR data minimization obligations. GA expected July 2026.

  • 🟡 eDiscovery Customer-Managed Key Support for Direct Export: Organizations subject to legal hold or regulatory audit obligations will gain the ability to control encryption keys on exported eDiscovery data, a requirement in some government and financial services contracts; plan for adoption ahead of the January 2027 GA date.

  • 🟡 Exchange Server SE CU1 Delay: The first cumulative update for Exchange Server Subscription Edition has slipped to the second half of 2026 with no firm date; organizations that planned infrastructure maintenance windows around this release need to revise their schedules and assess whether continued on-premises operation still aligns with their risk posture.

  • 🟢 Microsoft Purview Permissions Audit Log Improvements: Clearer audit logging for role and scoped-role access in the Purview portal will make it easier to demonstrate access governance to auditors; relevant to SOC 2 CC6 and HIPAA access controls, arriving September 2026.

  • 🟢 Organizational Data Granular Access Policy Controls: Admins will be able to restrict custom organizational data attributes to specific groups rather than broadcasting them to all employees, reducing the risk of sensitive workforce data being over-shared through Viva or Copilot-powered experiences.

  • 🟢 Expanded SaaS App Password Protection Coverage: Password risk visibility now extends to connected SaaS apps like Salesforce and ServiceNow, strengthening least-privilege enforcement across third-party platforms and helping close an implicit-trust gap that traditional identity hygiene programs often miss.

Sources: Exchange Server Security Updates Blog · Microsoft Security Response Center · Microsoft 365 Roadmap


What Your Employees Will Notice

  • Teams notifications can now be fully paused: Employees can temporarily silence all Teams notifications, not just individual chats or channels. This is a quality-of-life improvement; expect questions about how it differs from existing Do Not Disturb settings. Arriving September 2026.

  • Meeting organizer transfers in Outlook: Employees can hand off ownership of a meeting or recurring series to a colleague, who must accept before the transfer completes. This resolves a long-standing frustration for teams with recurring meetings whose original organizers have changed roles or left. Arriving September 2026.

  • Copilot in OneDrive gets more capable: Users will be able to ask Copilot to analyze files, produce summaries, and create dashboards or presentations directly from OneDrive on the web, without opening separate applications. Preview begins August 2026; expect questions from early adopters.

  • Copilot Notebooks now accepts more file types: Employees using Copilot Notebooks can now add plain-text files, Markdown documents, and rich text files as reference material, useful for teams working with README files, wikis, logs, and transcripts.

  • Planner private tasks get a dedicated home: Tasks marked private in Planner will now live in a unified private plan visible only to the individual user. No behavioral change is required, but employees may notice the organizational shift.

  • SharePoint link previews in Teams desktop: Sharing a SharePoint page link in a Teams chat or channel will now display a rich thumbnail preview card automatically. A small but visible change that improves context without any action needed.

  • Teams meetings: production tool control assignment: Meeting organizers can now designate which participants control production tools like Green Room and Manage What Attendees See. Relevant for teams running large events or webinars.

Sources: Microsoft 365 Roadmap · Teams Blog · Microsoft 365 Roadmap


What Your Help Desk Should Expect

  • Patch-related tickets: As security updates roll out across Exchange, Office, Teams, PowerShell, and Windows Server, some employees may experience application restarts, behavior changes, or prompts to update mobile apps. Expect a moderate uptick in “something changed” tickets over the next two weeks.

  • Teams notification pause questions: The new “pause all notifications” feature will generate questions from employees unclear on how it differs from Do Not Disturb or status settings. A brief communication or FAQ will reduce ticket volume.

  • Copilot in OneDrive questions: As preview access expands, employees will ask what Copilot can and cannot do within OneDrive. Help desk staff should know whether your organization has Copilot licenses enabled and which users have access.

  • Meeting organizer transfer process: Employees who discover the Outlook organizer-transfer feature will likely submit tickets if the transfer workflow is not intuitive or if the recipient does not accept promptly. Proactive communication about the accept-required step will help.

  • Exchange Server patch confirmation requests: IT leadership may receive inquiries from compliance officers or auditors asking for evidence that Exchange Server has been patched. Help desk and server teams should be prepared to produce patch confirmation documentation quickly.

Sources: Exchange Server Security Updates Blog · Microsoft 365 Roadmap · Microsoft 365 Roadmap


Cost & Licensing

  • Exchange Server 2016 and 2019 ESU enrollment is required to receive this month’s security patches. Organizations still running these end-of-life versions that have not enrolled in Microsoft’s Extended Security Update program cannot apply the August 2026 patches. ESU enrollment carries a per-server annual cost that increases each year; this is an additional budget item that should be tracked and weighed against the cost of migrating to Exchange Online or Exchange Server SE.

  • Defender for Cloud Apps connector required for expanded SaaS password protection. The new password risk visibility for Salesforce, ServiceNow, and other SaaS apps requires an active Defender for Cloud Apps app connector for each SaaS platform. Organizations should confirm whether their current licensing tier includes this capability before planning broad adoption.

  • Copilot license dependency for OneDrive AI features. The expanded Copilot capabilities in OneDrive require Microsoft 365 Copilot licenses. Organizations evaluating these features should account for per-seat licensing costs in their AI investment planning.

Sources: Exchange Server Security Updates Blog · Defender for Identity: Password Protection · Microsoft 365 Roadmap


Planning Horizon

  • Immediate (this week): August 2026 Exchange Server Security Updates: Authorize emergency patching for all on-premises Exchange servers and confirm ESU program enrollment status for Exchange 2016 and 2019 before patches can be applied.

  • Immediate (this week): Office, Teams, PowerShell, and Windows CVE Patch Deployment: Direct IT to confirm patch deployment status across all managed endpoints and servers, and request written confirmation for compliance documentation purposes.

  • Within 30 days: Exchange Server SE CU1 Delay and On-Premises Roadmap Review: Reassess your on-premises Exchange roadmap in light of the CU1 delay and rising ESU costs, and decide whether accelerating migration to Exchange Online changes your near-term budget or vendor timeline.

  • Within 30 days: Purview DLP File Quarantine for SharePoint and OneDrive (Preview): Engage your compliance and legal teams to evaluate this capability, define quarantine policies, and plan a pilot before GA so enforcement is ready when your regulators expect it.

  • Within 30 days: Zero Trust Identity Modernization Assessment: If your organization still relies primarily on on-premises Active Directory, commission a structured assessment of your identity modernization path; the combination of patch delays, ESU costs, and expanding cloud attack surfaces makes this a strategic priority, not a future-state discussion.

  • Within 90 days: eDiscovery Customer-Managed Key Support: If your contracts, regulatory obligations, or cyber insurance terms require customer-controlled encryption of exported legal data, assign a project owner to plan adoption ahead of the January 2027 GA date.

  • Within 90 days: Purview Permissions Audit Log Improvements: Notify your compliance and audit teams that enhanced role-access logging will be available in September 2026, and update your audit evidence collection procedures accordingly.

  • Within 90 days: Government Cloud: Teams Malicious URL Protection: If your organization operates in a government cloud environment, confirm that this Teams phishing-link protection feature is enabled when it reaches GA in October 2026, as it closes a gap that commercial cloud customers have had for some time.

Sources: Exchange Server Security Updates Blog · Microsoft Security Response Center · Microsoft 365 Roadmap


If You Take No Action

Exchange Server goes unpatched. Organizations running Exchange Server on-premises that delay applying the August 2026 security updates leave their email infrastructure exposed to known, publicly disclosed vulnerabilities. Exchange Server has historically been a primary target for ransomware operators and nation-state actors. A breach through an unpatched Exchange server can result in full mailbox access, lateral movement across the network, and regulatory notification obligations under HIPAA, GDPR, and state breach notification laws. If your organization is on Exchange 2016 or 2019 without ESU enrollment, you cannot apply these patches at all until enrollment is confirmed, creating a time-sensitive administrative dependency.

Office and Teams vulnerabilities remain exploitable. The three Office Graphics remote code execution vulnerabilities patched this week follow a well-documented attack pattern: an employee opens a malicious document received by email or downloaded from a compromised site, and the attacker gains control of that machine. Unpatched endpoints across a large workforce multiply this risk. Cyber insurers increasingly scrutinize patch cadence during claims review; delayed patching on publicly disclosed CVEs can become a coverage dispute.

Active Directory dependency limits your response options. Organizations that have not begun modernizing identity away from on-premises Active Directory face compounding risk as patch cycles lengthen, ESU costs rise, and cloud-native threats increase. An identity platform built entirely on-premises cannot enforce conditional access, continuous verification, or device compliance checks for cloud applications, leaving implicit-trust gaps that modern attacks are specifically designed to exploit. The cost of inaction here grows each quarter.

Sources: Exchange Server Security Updates Blog · Microsoft Security Response Center · Entra ID: Why Active Directory Alone Is No Longer Enough