Executive brief
Microsoft Exchange Server uses a weak or broken cryptographic algorithm that allows an attacker to intercept and read sensitive information transmitted over the network. This could expose confidential business communications, credentials, or other sensitive data that flows through the mail server.
Technical details
This vulnerability results from the use of a broken or risky cryptographic algorithm in Microsoft Exchange Server. An unauthorized attacker can exploit this weakness to disclose information transmitted over the network. The attack requires network access to Exchange Server communications. Successful exploitation leads to information disclosure without requiring authentication or user interaction. Microsoft has issued security updates to address this issue.
Affected products
- Microsoft Exchange Server
Timeline
- 2026-09-08: disclosed