Back

HIGH

Microsoft Exchange Server Remote Code Execution Vulnerability

Published Sep 8, 2026

Description

External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microsoft
Published Sep 8, 2026
Updated Oct 1, 2026
Reserved Aug 3, 2026
CISA Vulnrichment
Updated Sep 9, 2026
NVD
Status Awaiting Analysis
Modified Sep 9, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner microsoft
Published Sep 8, 2026
Updated Oct 1, 2026
Exploited since n/a
EUVD-2026-73124