Junglewise Threat Intelligence

CVE-2026-55007: Microsoft Exchange Server double free vulnerability

CVE-2026-55007 · Severity: high · CVSS 8.1 · Published 2026-09-08

Technologies: Microsoft Exchange Server. Vendors: Microsoft.

Executive brief

Microsoft Exchange Server is the email and collaboration platform used by many organizations to handle internal and external communications. A double free memory corruption vulnerability allows an unauthenticated attacker on a network to execute arbitrary code on the affected server, potentially compromising email data, enabling lateral movement within the organization, and disrupting email services.

Technical details

The vulnerability is a double free (memory corruption) in Microsoft Exchange Server, allowing unauthenticated remote code execution. The defect permits an attacker on the network to trigger the unsafe memory deallocation, leading to arbitrary code execution with the privileges of the Exchange process. No authentication is required and the attack is network-accessible, making it exploitable from outside the organization's perimeter. Patches are available from Microsoft via their Security Response Center.

Affected products

  • Microsoft Exchange Server

Timeline

  • 2026-09-08: disclosed: Published on NVD and Microsoft Security Response Center

References

Related threats