CVE Tools
Back to blog

September's Record Patch Tuesday Had Two Real Zero-Days. ZDI Ranked an Unexploited Exchange Bug Above Both.

CVE-2026-55007 lets an unauthenticated attacker execute code on Exchange Server just by sending an email with a malicious Visio attachment — no click, no Preview Pane. Microsoft rates the attack complexity "high"; ZDI's Dustin Childs called it the month's most important patch anyway.

September's Record Patch Tuesday Had Two Real Zero-Days. ZDI Ranked an Unexploited Exchange Bug Above Both.. CVE-2026-55007 lets an unauthenticated attacker execute code on Exchange Server just by sen
September's Record Patch Tuesday Had Two Real Zero-Days. ZDI Ranked an Unexploited Exchange Bug Above Both.. CVE-2026-55007 lets an unauthenticated attacker execute code on Exchange Server just by sen

A double-free hiding in your inbox

On September 8, 2026, Microsoft shipped its largest Patch Tuesday on record — somewhere between 972 and 997 CVEs depending on how you count Chromium-derived entries. Two of those bugs are confirmed zero-days, already added to CISA's Known Exploited Vulnerabilities catalog. Neither is the one Zero Day Initiative's Dustin Childs told people to drop everything for. That distinction went to CVE-2026-55007, an Exchange Server bug with no public exploit, no KEV listing, and — as of this writing — no confirmed victim. Here's why a bug nobody has caught in the wild outranked two that are actively being used.

8.1CVSS 3.1 scoreAV:N/AC:H/PR:N/UI:N — network, no privileges, no user interaction
0Public PoCs or KEV listingnot confirmed exploited as of Sept 20, 2026
9Exchange Server CVEs this Patch TuesdayCVE-2026-55007 plus four more rated High or Critical

How the attack works

CVE-2026-55007 is a double-free (CWE-415) in on-premises Exchange Server. Per Microsoft's advisory, reachable through multiple outlets that quoted it directly: an unauthenticated attacker sends an email with a malicious Visio attachment to the server. The code path that triggers isn't the mail client — it's Exchange's own content-indexing engine, which parses the attachment as part of normal message handling. Nobody has to open the email. Nobody has to preview it. The double-free fires while the server is doing its job.

CVE-2026-55007 attack chain

  1. Attacker sends email with malicious Visio attachment
  2. Exchange receives and queues the message
  3. Content-indexing engine parses the Visio file
  4. Server under sustained memory pressure?
  5. No — allocation succeeds, double-free doesn't trigger
  6. Yes — double-free triggers (CWE-415)
  7. Remote code execution on the Exchange server
A remote, unauthenticated attacker could get code execution on an affected Exchange server just by sending an email with a malicious Visio attachment. The code execution occurs when the server processes the mail – no need even for the Preview Pane.
— Dustin Childs, Zero Day Initiative, Sept 8, 2026

Ranked above two confirmed zero-days

The same Patch Tuesday fixed two vulnerabilities Microsoft confirms were already being exploited: CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack), both local elevation-of-privilege bugs, both added to CISA's KEV catalog with a September 22, 2026 deadline for federal agencies. Neither needs to reach across a network — both require an attacker who is already running code on the box. CVE-2026-55007 needs nothing but a mail server that accepts external email.

CVECVSS 3.1 vector / scoreAttack vectorPrivileges requiredConfirmed exploited?
CVE-2026-55007 (Exchange RCE)AV:N/AC:H/PR:N/UI:N — 8.1Network (email)NoneNot confirmed, not in KEV
CVE-2026-85880 (Windows ALPC EoP)AV:L/AC:L/PR:L/UI:N — 7.8LocalLow (already on the box)Yes — KEV, FCEB deadline Sept 22
CVE-2026-81963 (Windows Update Stack EoP)AV:L/AC:L/PR:L/UI:N — 7.8LocalLow (already on the box)Yes — KEV, FCEB deadline Sept 22

Two ways to read the same patch batch

What the scanner sees
  • CVSS 8.1 — High, not Critical
  • Attack complexity: High
  • No public PoC, no Metasploit, no Nuclei template
  • Not on CISA's KEV list
By risk-scoring defaults, this ranks below dozens of other September bugs, including plenty of 9.x scores.
What ZDI sees
  • Unauthenticated — no account, no foothold needed
  • Zero-click — fires during mail processing, before Preview Pane
  • One of nine Exchange bugs in the same cycle
  • "The attacker only needs to get it right once"
By blast-radius and prerequisite count, an Exchange server just needs to exist on the internet.

Not the only Exchange bug this month

CVE-2026-55007 shipped alongside four more High- or Critical-rated Exchange Server fixes in the same release — none currently flagged as exploited, all worth clearing in the same maintenance window.

CVETypeCWECVSS
CVE-2026-55007Remote code executionCWE-415 (double free)8.1 High
CVE-2026-69355Remote code executionCWE-73 (external control of file name/path)8.8 High
CVE-2026-69356SpoofingCWE-79 (cross-site scripting)9.3 Critical
CVE-2026-69641Elevation of privilegeCWE-862 (missing authorization)9.1 Critical
CVE-2026-69380Elevation of privilegeCWE-862 (missing authorization)8.1 High

Exchange keeps landing on CISA's KEV list

Query our own graph for Microsoft Exchange Server CVEs that CISA has ever added to KEV, and the pattern is stark: 20 entries stretching back to 2017, ten of them from the ProxyLogon/ProxyShell year alone. CVE-2026-55007 is not on that list — not yet, and maybe never. But Exchange's history is exactly why ZDI treats "not yet exploited" as a narrow window, not a reason to wait.

Microsoft Exchange Server CVEs added to CISA's KEV catalog, by year
20171201812020220211020223202312024120261
LabelValue
20171
20181
20202
202110
20223
20231
20241
20261
Our own index, n=20 total. 2026's sole entry so far is CVE-2026-42897 (spoofing, CVSS 8.1, added May); CVE-2026-55007 is not counted here.

What to do now

  1. Identify every on-prem Exchange Server 2019 CU14, CU15, and Subscription Edition RTM build in your environment — Exchange Online is not affected.
  2. Update CU14 builds to 15.02.1544.046 or later, CU15 builds to 15.02.1748.051 or later, and Subscription Edition RTM to 15.02.2562.049 or later.
  3. Apply the fix even if content indexing feels like a low-priority service — it runs by default on every mailbox server.
  4. Clear the other four Exchange fixes from the same release (CVE-2026-69355, -69356, -69641, -69380) in the same maintenance window; none has a published workaround either.
  5. Don't deprioritize this because it's not in KEV yet — 20 previous Exchange CVEs eventually got there, several years after disclosure.

CVE and KEV data as of September 20, 2026

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store