Microsoft says the growing volume of vulnerabilities identified with AI-powered security tools is contributing to delays in the first Cumulative Update (CU1) for Exchange Server Subscription Edition.
The Exchange team is prioritizing the validation, reproduction, remediation, and testing of newly reported security issues while continuing to release security updates each month.
Microsoft originally expected CU1 in the first half of 2026, later moving the target to the second half of the year. The company now says it has no release date, explaining that
Steven Swift, Managing Director, Suzu Labs:
“The problem with using AI to “find vulnerabilities” is that its relatively easy for a model to hallucinate that it’s found a vulnerability, and if you try to use AI to validate the vulnerability, it will refuse to do so because of its safety tuning. This means teams that are trying to actually process and take these requests seriously end up with an impossible amount of work, trying to prove countless negatives.
“On one hand, its a good sign that we’re being told security is being taken seriously. If delays are needed to avoid shipping known vulnerabilities, I generally support that. On the other hand, its very easy to blame AI for delays that are due to other factors. Its hard to tell which is which from the outside. Educated guess here is that Microsoft is looking at a bit of both. Its pretty easy to waste cycles on low value AI generated vulnerability reports, and its always easy to mis-manage a project, and end up behind schedule.
“We should keep in mind that we’ve seen a steady increase in CVEs being published over the past 10 years, before AI became big. We already had a well established industry dedicated to vulnerability management, with tools designed to detect and help remediate vulnerabilities in code. Stacked on top of this now is vibe coded slop being pushed out in bulk by developers, who have been pressured to utilize AI in an effort to improve output. But while AI can push code out faster, it does not mean it does better.
“AI is currently better at generating code and running test cases to validate functionality, than it is in proving that the code it wrote isn’t vulnerable. Part of this is training data and tuning. Its much more straight forward to validate functionality. There’s no test you can write that will prove a negative though. At best, you can match patterns and some known common weaknesses. As AI improves, it will get better at writing secure code. But if current trends hold, and models continue to refuse to validate potential vulnerabilities, it puts a cap on how useful models can be for detections.”
John Strand, Owner, Black Hills Information Security, Inc.:
“This is concerning. If we have so many vulnerabilities coming in that it’s actually delaying cumulative updates and patches from vendors, that’s a sign the system is starting to seize up a little bit.
“And there’s a question that keeps rolling around in my head as we continue to see these issues with companies around the world. Did we really think AI was going to lower security headcount across the industry?
“What we’re seeing is the opposite. AI is dramatically increasing the volume and velocity of security work that needs to be done. That means we’re going to need more security professionals, not fewer. And we especially need to be bringing in people at the junior level, training them, giving them experience, and building them into the senior security professionals we’re going to desperately need in the years ahead.”
Related
This entry was posted on August 17, 2026 at 3:32 pm and is filed under Commentary with tags Microsoft. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Microsoft says AI-discovered security flaws are delaying Exchange update
Microsoft says the growing volume of vulnerabilities identified with AI-powered security tools is contributing to delays in the first Cumulative Update (CU1) for Exchange Server Subscription Edition.
The Exchange team is prioritizing the validation, reproduction, remediation, and testing of newly reported security issues while continuing to release security updates each month.
Microsoft originally expected CU1 in the first half of 2026, later moving the target to the second half of the year. The company now says it has no release date, explaining that
Steven Swift, Managing Director, Suzu Labs:
“The problem with using AI to “find vulnerabilities” is that its relatively easy for a model to hallucinate that it’s found a vulnerability, and if you try to use AI to validate the vulnerability, it will refuse to do so because of its safety tuning. This means teams that are trying to actually process and take these requests seriously end up with an impossible amount of work, trying to prove countless negatives.
“On one hand, its a good sign that we’re being told security is being taken seriously. If delays are needed to avoid shipping known vulnerabilities, I generally support that. On the other hand, its very easy to blame AI for delays that are due to other factors. Its hard to tell which is which from the outside. Educated guess here is that Microsoft is looking at a bit of both. Its pretty easy to waste cycles on low value AI generated vulnerability reports, and its always easy to mis-manage a project, and end up behind schedule.
“We should keep in mind that we’ve seen a steady increase in CVEs being published over the past 10 years, before AI became big. We already had a well established industry dedicated to vulnerability management, with tools designed to detect and help remediate vulnerabilities in code. Stacked on top of this now is vibe coded slop being pushed out in bulk by developers, who have been pressured to utilize AI in an effort to improve output. But while AI can push code out faster, it does not mean it does better.
“AI is currently better at generating code and running test cases to validate functionality, than it is in proving that the code it wrote isn’t vulnerable. Part of this is training data and tuning. Its much more straight forward to validate functionality. There’s no test you can write that will prove a negative though. At best, you can match patterns and some known common weaknesses. As AI improves, it will get better at writing secure code. But if current trends hold, and models continue to refuse to validate potential vulnerabilities, it puts a cap on how useful models can be for detections.”
John Strand, Owner, Black Hills Information Security, Inc.:
“This is concerning. If we have so many vulnerabilities coming in that it’s actually delaying cumulative updates and patches from vendors, that’s a sign the system is starting to seize up a little bit.
“And there’s a question that keeps rolling around in my head as we continue to see these issues with companies around the world. Did we really think AI was going to lower security headcount across the industry?
“What we’re seeing is the opposite. AI is dramatically increasing the volume and velocity of security work that needs to be done. That means we’re going to need more security professionals, not fewer. And we especially need to be bringing in people at the junior level, training them, giving them experience, and building them into the senior security professionals we’re going to desperately need in the years ahead.”
Share this:
Like this:
Related
This entry was posted on August 17, 2026 at 3:32 pm and is filed under Commentary with tags Microsoft. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.