Back Senserva CVE-2026-45503: the Microsoft Exchange Server Subscription fix is KB5094139 (CVSS 8.8)
High severity Microsoft vulnerability, CVSS 8.8. Fixed by 4 Microsoft security updates.
CVE-2026-45503 is a high severity Microsoft vulnerability with a CVSS score of 8.8. Microsoft has shipped the fix: deploy one of the 4 updates below from the Microsoft Update Catalog, and see where this CVE sits against the rest on the patch tracker.
Not in the CISA KEV catalog. EPSS exploit probability 5.6%. CVSS 8.8 (High).
This CVE is among the lower half of tracked Microsoft CVEs by EPSS exploit probability.
Moderate priority: schedule it in your normal patch cycle. In Intune or Defender, confirm whether the fixing updates KB5094139, KB5094140, KB5094142, KB5094144 are installed across the affected products. Senserva does this automatically across your tenant and flags every missing patch.
Apply the Microsoft security updates below to fix CVE-2026-45503. Each KB page links to the Microsoft Update Catalog download for every affected product.
It is not currently listed in the CISA Known Exploited Vulnerabilities catalog. Its EPSS score puts the probability of exploitation in the 30 days at 5.6%.
Microsoft fixed CVE-2026-45503 in KB5094139, KB5094140, KB5094142, KB5094144. Download from the Microsoft Update Catalog, or let Intune, Windows Update, or WSUS deliver it.
Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server Subscription Edition RTM.
If you are patching CVE-2026-45503, the same updates also fix these:
Want every Microsoft CVE and the patches that fix it, ranked by real-world risk? See the Microsoft Patch Tracker .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
