CVE-2026-55007 Microsoft Exchange Server Remote Code Execution Vulnerability
8.1
Analysis on rafaelpfister.ch
- Article · October 7, 2026 September 2026 Exchange security updates: nine vulnerabilities, wrapper issue fixed, v2 released The September SU addresses nine vulnerabilities in Exchange SE and 2019 (eight in Exchange 2016), including a spoofing vulnerability with CVSS 9.3, and fixes the wrapper issue in hybrid environments. Version 2 followed on October 2 with an additional CVE; there are also three known issues with workarounds and a SettingOverride that should now be removed.
- Article · October 7, 2026 Exchange Security Update September 2026 v2: Early Fix for CVE-2026-96940 On October 2, 2026, Microsoft released version 2 of the September SUs for Exchange SE, 2019, and 2016. It additionally closes CVE-2026-96940, an elevation-of-privilege vulnerability with CVSS 8.8 and an “Exploitation More Likely” assessment. Microsoft recommends installing v2 as soon as possible, including on servers with the first September SU.
Vendor description
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. Reference data
- Vendor
- Microsoft
- Affected products
- Microsoft Exchange Server 2019 Cumulative Update 14
- Microsoft Exchange Server 2019 Cumulative Update 15
- Microsoft Exchange Server Subscription Edition RTM
- CVSS 3.1
- 8.1 (HIGH)
- Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C- Weakness type
- CWE-415: Double Free
- Published
- September 8, 2026