Junglewise Threat Intelligence

CVE-2026-69355: Microsoft Exchange Server external control of file name or path

CVE-2026-69355 · Severity: high · CVSS 8.8 · Published 2026-09-08

Technologies: Microsoft Exchange Server. Vendors: Microsoft.

Executive brief

Microsoft Exchange Server is a widely-deployed email and collaboration platform used by enterprises to manage corporate communications. A vulnerability in file path handling allows an authorized attacker to execute arbitrary code remotely on affected servers, potentially leading to complete compromise of the email system and access to sensitive business communications.

Technical details

This vulnerability is an external control of file name or path issue (CWE-426 class) in Microsoft Exchange Server. An authorized attacker can exploit improper file path validation to execute arbitrary code with the privileges of the Exchange process. The attack requires network connectivity to an affected Exchange Server and prior authentication; no additional user interaction is needed. Successful exploitation grants the attacker remote code execution on the server, enabling full system compromise. Microsoft has released security updates to address this vulnerability.

Affected products

  • Microsoft Exchange Server

Timeline

  • 2026-09-08: disclosed
  • patched: Security update released by Microsoft

References

Related threats