Dealing with machine-made bug backlog makes it hard to find a moment to deliver promised subscription service

Microsoft has acknowledged a delay in the release of Cumulative Update 1 (CU1) for Exchange Server Subscription Edition (SE), attributing the setback to an increased volume of security vulnerabilities identified by artificial intelligence tools. The company’s Exchange team addressed customer inquiries in a post titled “Where is Exchange SE CU1 anyway?” published last Thursday, confirming that the update, initially projected for release by the end of the first half of calendar year 2026 and later revised to the second half, is now without a definitive release date.
Exchange SE is the subscription-based iteration of Microsoft’s email server, and Cumulative Updates are comprehensive packages that bundle all recent bug fixes, new features, and deprecated code removals. These updates are typically issued once or twice annually, serving as an alternative to applying individual patches for some users.
The delay in CU1’s availability for a subscription product has prompted questions regarding the model’s benefits. Microsoft explained that various executives have previously discussed the company’s use of AI tools to discover product vulnerabilities. The Exchange development team is actively engaged in validating these reported issues, reproducing them, developing fixes, testing for regressions, and releasing monthly updates.
This intensified focus on security aligns with Microsoft’s commitment to "prioritize security above all else," a stance adopted following an attack on Exchange by suspected Chinese operatives that drew criticism from the U.S. government.
The Exchange team stated that while managing the ongoing influx of security issues, they are also progressing with CU1 development. The team is integrating monthly security payloads into the internal CU1 build and plans to release the update once a stable point is reached and a month passes without urgent security updates.
This approach aims to prevent the scenario of releasing CU1 only to immediately follow it with another update containing new security fixes, which would impose a double workload on organizational administrators. Internally, ensuring the thorough testing of two major releases—a security update and a Cumulative Update—to maintain quality and prevent oversights is a significant challenge, as CU1 must encompass all previous releases since the RTM (Release to Manufacturing) version.
While administrators may appreciate Microsoft’s effort to avoid multiple major updates, the indefinite timeline for CU1’s release, contingent on a month free of “pressing security payload,” leaves uncertainty. The company’s post concluded with the statement, “In short: Exchange SE CU1 is coming; we do not have a date to give you. But we did not forget about it.” The situation suggests that the impact of AI-powered bug detection on product development timelines may not have been fully anticipated.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.