ZeroHour

CVE-2026-69355

large

Authenticated RCE in Microsoft Exchange Server via external file path control

CVSS 3.1
8.8 high
EPSS
<1%p56
Published
()
Modified
AI analysis

CVE-2026-69355 is a file name or path control flaw (CWE-73) in Microsoft Exchange Server in which an externally supplied file name or path is used without proper validation. An attacker who already holds a valid, low-privilege account on the affected Exchange environment can trigger the flaw remotely over the network by supplying a crafted file path, gaining arbitrary code execution on the server with high impact on confidentiality, integrity, and availability (CVSS 8.8). Because privileges are required, this is not an unauthenticated remote code execution, but any organization running a vulnerable on-prem Exchange Server that exposes Exchange services to account holders is in scope. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS currently estimates only a 0.8% chance of exploitation in the next 30 days, so there is no confirmed in-the-wild exploitation at this time.

What to do: Monitor Microsoft's advisory and apply the released Exchange Server security update as soon as it is available, prioritizing internet-facing Exchange servers. Because exploitation requires a valid account, review for compromised or low-privilege accounts with Exchange access and restrict which accounts can reach Exchange services from external networks. Until patched, limit exposure of OWA/EWS endpoints to trusted networks and watch server logs for unexpected file path parameters or anomalous process activity.

Affected
Microsoft Exchange Server
Estimated exposure
largetens of thousands of internet-exposed Exchange servers, with a total on-prem installed base plausibly in the hundreds of thousands of deployments — Internet-wide scans of publicly exposed Exchange services (OWA/EWS endpoints) have historically shown on the order of 50,000-100,000 reachable servers, with a much larger total on-prem installed base across organizations, though the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

Weakness
CWE-73
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.