Executive brief
Microsoft Exchange Server is an email and collaboration platform used by organizations to manage corporate communications and data. An attacker can exploit an uncontrolled recursion vulnerability in the server to trigger a denial of service, disrupting email availability for affected organizations without requiring authentication or local access.
Technical details
The vulnerability is an uncontrolled recursion flaw in Microsoft Exchange Server that allows remote attackers to cause a denial of service condition. The attack is network-accessible and requires no authentication or user interaction. By exploiting the recursive behavior in the affected component, an attacker can exhaust server resources and crash the service, rendering email unavailable to users. A patch is expected to be available from Microsoft through their Security Update Guide.
Affected products
- Microsoft Exchange Server
Timeline
- 2026-09-08: disclosed