CVE-2026-55007: Microsoft Exchange Server Remote Code Execution Vulnerability

Overview

Severity
High (CVSS 8.1)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Remote Code Execution
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2026-Sep
Released
2026-09-08
EPSS Score
0.73% (percentile: 52.0%)

Description

Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

FAQ

How could an attacker exploit this vulnerability? An unauthenticated attacker could send a specially crafted Visio attachment to an affected Exchange server. The server could process the attachment during content indexing, and successful exploitation could allow the attacker to execute code on the server. User interaction is not required. According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation requires the target system to be under sustained low-memory (memory pressure) conditions, which are not commonly present in normal operation. This makes the vulnerability difficult to reliably trigger, as the attacker must first induce or wait for a constrained memory state before exploitation becomes possible.

Affected Products (3)

ESU

  • Microsoft Exchange Server 2019 Cumulative Update 14
  • Microsoft Exchange Server 2019 Cumulative Update 15

Server Software

  • Microsoft Exchange Server Subscription Edition RTM

Security Updates (1)

Acknowledgments

Anonymous, Anonymous

Revision History

  • 2026-09-08: Information published.