Exchange CU1 delayed further as Microsoft races to verify AI-found flaws Microsoft has delayed the first Cumulative Update (CU1) for Exchange Server Subscription Edition for the second time, now without a committed timeline, as its engineers race to validate a growing volume of security findings from AI-assisted code scanning. The company initially targeted the end of the first half of 2026, then revised to the second half, and now offers no date. Principal analyst Manoj Chandra Jha of Nord-IQ Research advises enterprises to treat CU1 as a trigger-based project and maintain readiness independent of Microsoft's release calendar. AI-based assistants and agents are generally supposed to expedite software development lifecycles. For Microsoft’s Exchange team, it may be doing the opposite, in turn leaving enterprise IT teams waiting for an update that will require extensive compatibility testing before implementation. In response to customer questions, Microsoft said in a blog post https://techcommunity.microsoft.com/blog/exchange/where-is-exchange-se-cu1-anyway/4546837 that it was again being forced to delay the first Cumulative Update CU1 for its Exchange Server Subscription Edition https://www.computerworld.com/article/4016382/microsofts-exchange-server-subscription-edition-now-ga-to-replace-standalone-exchange-2016-and-2019.html because its engineers were racing against time to validate a growing volume of security findings surfaced through AI-assisted code scanning. “Over the last few months, various Microsoft execs made statements explaining how Microsoft is leveraging a variety of AI tools to help find vulnerabilities in our products examples of such announcements can be found here https://blogs.windows.com/windowsexperience/2026/07/09/evolving-windows-vulnerability-management-to-meet-the-speed-of-ai-powered-discovery/ , here https://www.microsoft.com/en-us/security/blog/2026/04/22/ai-powered-defense-for-an-ai-accelerated-threat-landscape/ and here https://www.microsoft.com/en-us/msrc/blog/2026/04/strengthening-secure-software-global-scale-how-msrc-is-evolving-with-ai ,” the company wrote. “Many teams, Exchange Server included, are working through reported issues – which includes validation that they are real security issues, reproducing, fixing, testing for regressions / issues after fixes are deployed and releasing updates monthly,” it added. The company had initially indicated that CU1 would arrive by the end of the first half of 2026, before revising its target to the second half of 2026. The latest delay, where Microsoft is yet to offer any timeline, therefore marks the second time the hyperscaler has pushed back its expected release window. A Cumulative Update CU is a periodically released package for Exchange Server that consolidates recent bug fixes and security updates, while also potentially introducing new features, architectural changes or removing deprecated components. Unlike the monthly security updates that Microsoft has continued to issue for Exchange Server Subscription Edition SE consistently, CUs represent a more substantial update to the server software and are typically released once or twice a year. This gives enterprise administrators the option of adopting a consolidated package of fixes and changes rather than managing individual updates separately, although the broader scope of a CU also means enterprises need to conduct more extensive testing before deployment. The second revision of the CU1 release timeline combined with the unavailability of a committed shipping date or month, according to Manoj Chandra Jha https://www.linkedin.com/in/manoj-chandra-jha-b5ab0a13/ , principal analyst at Nord-IQ Research, should be reason enough for enterprises to course correct. Enterprises should start tracking the monthly security update cadence as their operational patch baseline, and treat CU1 as a discrete, trigger-based project ,not a scheduled release until Microsoft provides a firmer signal,” Jha said. For enterprises that are waiting for a commitment or CU1’s release to begin their preparation, however, the delay shouldn’t mean standing still, Jha pointed out. “With no committed ship date, CIOs should separate CU1 readiness from Microsoft’s release calendar by maintaining a test environment, inventorying and pre-validating authentication, APIs and management tools, and establishing a fast-track change-approval process that can be activated once Microsoft announces the update,” Jha noted. Microsoft’s Exchange isn’t the only company division confronting the unintended consequences of AI-driven increases in software output. GitHub, which helped popularize AI-assisted coding through its vibe coding tool Copilot, has also been grappling with the volume and quality of code being generated by AI tools. In February, GitHub considered https://www.infoworld.com/article/4127156/github-eyes-restrictions-on-pull-requests-to-rein-in-ai-based-code-deluge-on-maintainers.html allowing repository maintainers to restrict or even disable pull requests after maintainers warned that a surge of low-quality, often AI-generated submissions was overwhelming open-source projects. The problem was not simply that AI was generating more code, but that humans were struggling to review and manage the resulting flood of contributions. GitHub subsequently introduced Stacked PRs https://www.infoworld.com/article/4158575/github-adds-stacked-prs-to-speed-complex-code-reviews.html in April, saying the feature was designed to help developers manage larger and more complex code changes as AI-assisted development increases the volume of code requiring review. Its rationale was to break larger changes into smaller units, in turn making them easier to review and merge. AWS too identified a similar issue and in June added release management features to its DevOps Agent to help teams validate, test, and review AI-generated code before deployment. More recently, AI-based Code Review platform CodeRabbit also added new features https://www.infoworld.com/article/4208611/coderabbit-targets-ai-generated-code-overload-with-agentic-change-management.html to help developers sort and prioritize pull requests in wake of the growing volume and complexity of code changes generated by vibe coding agents. This mismatch between the volume of AI-generated output and the amount of human attention available to assess it extends beyond code review. Earlier, in May, GitHub also said it had seen a sharp increase in low-quality security submissions to its bug bounty program, driven in part by newer generative AI tools. The company responded by scaling back cash rewards https://www.infoworld.com/article/4173227/github-scales-back-bug-bounties-reminds-users-security-is-their-responsibility-too-2.html for reports with low security impact and asking researchers to focus on vulnerabilities that represent meaningful security risks.