ZeroHour

CVE-2026-69380

large

Missing Authorization Flaw in Microsoft Exchange Server Enables Privilege Escalation

CVSS 3.1
8.1 high
EPSS
<1%p51
Published
()
Modified
AI analysis

Microsoft Exchange Server contains a missing-authorization vulnerability (CWE-862) in which a network-accessible component fails to properly verify a caller's permissions before handling a request. An attacker who already holds valid low-privileged credentials can send crafted requests over the network to trigger the flaw and elevate privileges. The CVSS ratings show high confidentiality and integrity impact, so successful elevation likely grants access to and control over sensitive mailbox or server resources. Organizations running on-premises Microsoft Exchange Server are affected, whether the server is internet-exposed or reachable by internal users with standard accounts. As of the available data there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates a 0.7% probability of exploitation within 30 days; it was addressed in Microsoft's large Patch Tuesday release per related coverage.

What to do: Apply the Exchange Server security update from Microsoft's advisory for this CVE as soon as it is available for your installed cumulative update. Because exploitation requires an authenticated low-privileged user, restrict external access to OWA/EWS and other Exchange web endpoints (VPN or IP allowlists) and audit for unexpected privilege changes or new privileged accounts. Follow Microsoft's advisory for exact affected and fixed versions, as none were specified in this data.

Affected
Microsoft Exchange Server (on-premises)
Estimated exposure
largetens of thousands of internet-exposed on-prem Exchange servers (roughly 50k–100k per public scans) — Public internet scans have historically counted on the order of 50,000–100,000 exposed Exchange/OWA endpoints, and the on-prem Exchange installed base across hundreds of thousands of organizations remains large though declining as tenants…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

Microsoft’s Biggest Patch Tuesday: 974 CVEs, 2 Zero-Days and 20 Wormable Bugs

Microsoft's record September 2026 Patch Tuesday fixes 974 CVEs, including two exploited Windows privilege-escalation zero-days and 20 wormable bugs.

Microsoft's September 2026 Patch Tuesday fixes a record 974 CVEs, including two actively exploited zero-days: CVE-2026-85880, an ALPC heap buffer overflow, and CVE-2026-81963 in the Windows Update Stack, both CVSS 7.8 local privilege escalations. It also addresses an unauthenticated Exchange RCE (CVE-2026-55007) triggered by Visio attachment content indexing under memory pressure, an RDP use-after-free (CVE-2026-69525, CVSS 9.8), and 20 wormable flaws in DNS, DHCP, SMB, Active Directory, and other components. ZDI attributed the rising volume partly to AI-assisted vulnerability discovery, noting no corresponding spike in active exploits yet.

Security Affairs · 6d agoVulnerability in the wildCVE-2026-85880CVE-2026-81963CVE-2026-55007+3 CVEs1