CVE-2026-55007
Microsoft Exchange Server Remote Code Execution Vulnerability
Description
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
In plain language
AI Act nowCVE-2026-55007 is a Microsoft Exchange Server bug that can let an attacker remotely run code; if you run Exchange Server 2019 CU14/CU15 or Exchange Server Subscription Edition RTM, you should treat this as urgent and update to the fixed versions.
CVE-2026-55007 is a remote code execution vulnerability in Microsoft Exchange Server caused by a memory-safety issue (double free, CWE-415), reachable over the network without authentication; fixed releases are Exchange 2019 CU14→CU15.02.1544.046, CU15→15.02.1748.051, and Exchange Subscription Edition RTM→15.02.2562.049.
What to do now
- Check which Microsoft Exchange Server version and cumulative update you are running (e.g., Exchange 2019 CU14, CU15, or Subscription Edition RTM).
- If you are on Exchange 2019 Cumulative Update 14, upgrade to 15.02.1748.051.
- If you are on Exchange 2019 Cumulative Update 15, upgrade to 15.02.1748.051.
- If you are on Exchange Server Subscription Edition RTM, upgrade to 15.02.2562.049.
- After updating, verify Exchange services are healthy and follow your normal change-management/rollback plan.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft выпустила патчи для почти 1000 уязвимостейru-ru·Хакер (xakep.ru)· Exploited Windows patch-tuesday
- September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successoren-us·Help Net Security· Exploited Windows Update Stack patch-tuesday
- Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Daysen·The Hacker News· Exploited Windows zero-day
- Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Daysen-us·SecurityWeek· Exploited Windows ALPC Tenable
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysen-us·BleepingComputer· Exploited Windows patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-55007 and every CVE in our database. Create a free account — no credit card required.
Create Free Account