ZeroHour

CVE-2026-69641

mass

Missing Authorization Privilege Escalation in Microsoft Exchange Server

CVSS 3.1
9.1 critical
EPSS
<1%p56
Published
()
Modified
AI analysis

Microsoft Exchange Server contains a missing authorization flaw (CWE-862), meaning a privileged operation does not properly verify whether the caller is permitted to perform it. The flaw is reachable over the network, and the CVSS vector indicates the attacker must already hold high privileges (PR:H) — e.g., an Exchange administrator-level account — before triggering it, with impact extending beyond the vulnerable component's security scope (S:C). A successful attacker elevates their privileges into a broader scope, with high impact on confidentiality, integrity, and availability. Any organization running Microsoft Exchange Server is potentially affected; the available data does not enumerate specific affected versions or builds. There is currently no known public proof-of-concept, no CISA KEV listing, and EPSS estimates only about a 0.8% probability of exploitation within 30 days, so exploitation is not yet observed.

What to do: Apply the Microsoft security update for Exchange Server addressing CVE-2026-69641 when available, and verify your installed build against the affected-versions table in Microsoft's advisory (not enumerated in this data). Until patched, restrict and audit high-privileged Exchange administrative accounts, since exploitation requires that level of access, and monitor logs for unexpected privilege or scope changes. Watch this dashboard for changes in EPSS or KEV status that would indicate active exploitation.

Affected
Microsoft Exchange Server
Estimated exposure
masson the order of hundreds of thousands of on-prem Exchange Server deployments worldwide (est.) — Exchange Server retains a very large on-prem installed base across enterprises and public-sector organizations, and public internet scans routinely show tens of thousands of exposed Exchange OWA/EWS endpoints, though the PR:H requirement…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.