Executive brief
Microsoft Exchange Server is an email and collaboration platform used by organizations to manage business communications. This vulnerability allows an authorized attacker to bypass security controls and tamper with data flowing through the system over a network, potentially compromising the confidentiality and integrity of email and calendar data.
Technical details
The vulnerability is an authorization bypass in Microsoft Exchange Server caused by improper validation of user-controlled cryptographic keys. An authenticated attacker can exploit this flaw to bypass authorization checks and perform data tampering over the network. The attack requires prior authentication and network access to the Exchange Server. Successful exploitation allows an attacker to modify data that should be protected by access controls. A patch is available from Microsoft.
Affected products
- Microsoft Exchange Server
Timeline
- 2026-09-08: disclosed