ZeroHour

CVE-2026-69378

mass

Uncontrolled Recursion DoS in Microsoft Exchange Server (pre-auth)

CVSS 3.1
7.5 high
EPSS
1%p64
Published
()
Modified
AI analysis

CVE-2026-69378 is an uncontrolled recursion flaw (CWE-674) in Microsoft Exchange Server that can be triggered over the network without authentication. An attacker sends crafted network input that drives a recursive routine to excessive depth, exhausting stack/server resources and crashing or hanging the affected Exchange service. The impact is availability only: a remote denial of service with no data exposure or tampering (CVSS 3.1 7.5, AV:N/AC:L/PR:N/UI:N, availability high). Any organization running an affected on-premises Exchange Server build reachable from untrusted networks is affected; the source data does not specify exact version ranges, so consult Microsoft's advisory for build details. There is currently no known public proof of concept, it is not listed in CISA's KEV, and EPSS estimates about a 1.1% chance of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69378 to all on-premises Exchange servers as soon as it is released, checking Microsoft's advisory for the exact affected builds and fixed versions. Until patched, restrict untrusted network access to Exchange services (such as OWA/EAC endpoints) using VPN, reverse proxy, or firewall rules, and rate-limit unauthenticated traffic to reduce DoS risk. Monitor Microsoft's advisory and threat feeds for mitigations and any emergence of a public PoC, since pre-auth DoS flaws in Exchange are frequently probed once details surface.

Affected
Microsoft Exchange Server
Estimated exposure
massLikely on the order of 100,000+ internet-facing Exchange servers (public scans have long shown Exchange OWA/server endpoints in the tens to hundreds of… — Internet-wide scan datasets (e.g., Shodan/Censys/ShadowServer) have repeatedly counted Exchange endpoints exposed to the internet in the tens to hundreds of thousands, and Microsoft's on-prem Exchange installed base spans hundreds of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.

Weakness
CWE-674
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.