CVE-2026-69378
massUncontrolled Recursion DoS in Microsoft Exchange Server (pre-auth)
CVE-2026-69378 is an uncontrolled recursion flaw (CWE-674) in Microsoft Exchange Server that can be triggered over the network without authentication. An attacker sends crafted network input that drives a recursive routine to excessive depth, exhausting stack/server resources and crashing or hanging the affected Exchange service. The impact is availability only: a remote denial of service with no data exposure or tampering (CVSS 3.1 7.5, AV:N/AC:L/PR:N/UI:N, availability high). Any organization running an affected on-premises Exchange Server build reachable from untrusted networks is affected; the source data does not specify exact version ranges, so consult Microsoft's advisory for build details. There is currently no known public proof of concept, it is not listed in CISA's KEV, and EPSS estimates about a 1.1% chance of exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-69378 to all on-premises Exchange servers as soon as it is released, checking Microsoft's advisory for the exact affected builds and fixed versions. Until patched, restrict untrusted network access to Exchange services (such as OWA/EAC endpoints) using VPN, reverse proxy, or firewall rules, and rate-limit unauthenticated traffic to reduce DoS risk. Monitor Microsoft's advisory and threat feeds for mitigations and any emergence of a public PoC, since pre-auth DoS flaws in Exchange are frequently probed once details surface.
| Microsoft Exchange Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.
- Weakness
- CWE-674
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.