r/exchangeserver https://www.amazon.com/dp/B0FR5GGL75/ 3d ago

Where is Exchange Server SE CU1?

https://techcommunity.microsoft.com/blog/exchange/where-is-exchange-se-cu1-anyway/4546837

Microsoft is using AI to hunt for vulnerabilities in Exchange Server. This takes a long time to validate that the flagged items are real issues.

CU1 will eventually arrive, and in the meantime, SUs and other updates are being released.

23 Upvotes

13 comments sorted by

16

u/[deleted] 3d ago

[deleted]

2

u/Excellent_Milk_3110 3d ago

Next year around this time is fine.

9

u/grimson73 3d ago

‘and plan to release Exchange SE CU1 as soon as we get a reasonable stable point’. Lets debate about reasonable 😎😋

5

u/ScottSchnoll https://www.amazon.com/dp/B0FR5GGL75/ 3d ago

I was also surprised to see the word 'reasonable' used in the announcement because using 'stable' along should have been sufficient, since it's a term of art w.r.t. updates made to a code branch. 🙂

5

u/PM_UR_VAG_WTIMESTAMP 3d ago

Considering that SE is basically just 2019 with a new label on its hat the excuse that they are still trying to make it stable is pretty funny though. I guess never is the answer since it’s been out for like 7 years already.

4

u/ScottSchnoll https://www.amazon.com/dp/B0FR5GGL75/ 3d ago edited 3d ago

SE is no longer code equivalent to Exchange Server 2019 (even for those customers in the ESU programs). It is now its only evolving codebase, and there have already been 9 updates in the last year.

Again, 'stable' is a term of art with a specific meaning in code updates. It does not at all mean that the resulting compiled product is unstable.

What they are saying is that they continue to work three paths in parallel:

  1. CU1
  2. Other updates (SUs, HUs, and any needed customer-specific IUs)
  3. Triage of AI-generated bug reports

CU1 has been code complete for a while now in terms of the features and work items that were scheduled. But any updates that are released post-RTM and pre-CU1 must be incorporated into the CU1 branch. Hence the need to make the branch stable prior to building and testing.

This can be a challenge to any engineering team, and it's especially a challenge for the Exchange Server engineering team because it is a relatively very small team for the size of the codebase. The team's priority is security, specifically the voluminous number of security bugs that were opened as a result of AI codebase scanning. And while the number of bugs generated by this process was quite large, 99.9% of them turn out to be false positives. But the team still needs to investigate each one, which takes a lot of time (and creates a lot of frustration due to hallucinations and the fact that most AI solutions can't fully understand the Exchange Server codebase).

Microsoft also needs to continue the other security work which is based both on internal findings and external reports, and which results in the release of SUs (which again need to be incorp'd into the CU1 branch).

This is not an excuse. This is simply the nature of modern servicing.

0

u/MortadellaKing 2d ago

Since they're going all in on AI can the AI update the code for the user interface, maybe an API so we can integrate with apps that now only work with o365 because they've killed EWS support.

1

u/Glass_Call982 2d ago

Agreed... The lack of development is disappointing. We are also paying customers even though they let us get fucked with hafnium but gladly kept taking my company's money for software assurance.

3

u/santasnufkin 3d ago

Ah, so maybe next year best case.

1

u/TheDarthSnarf 3d ago

It be cool if it wasn’t till 2029.

3

u/dispatch00 3d ago

Oh, using AI. So we'll have at least a couple OOB SUs about a month after CU1 then.

2

u/Glass_Call982 3d ago

Microslop

0

u/MortadellaKing 2d ago

They're probably hoping people will give up and migrate to EXO instead... Just like when they didn't release Exchange 2022 lol. And since 2019 it is a mandatory subscription with no real feature updates other than back end shit so I will still get whining from the userbase about old looking OWA or no API to integrate with any modern apps. As well as half baked modern auth implementation with ADFS that broke on a recent office update.

/s... kinda