CyberICT

CVE-2026-69355

Microsoft · Published September 8, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Microsoft Exchange Server Remote Code Execution Vulnerability. External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

Affected Products

  • Microsoft Exchange Server 2019 Cumulative Update 15
  • Microsoft Exchange Server 2019 Cumulative Update 14
  • Microsoft Exchange Server 2016 Cumulative Update 23
  • Microsoft Exchange Server Subscription Edition RTM

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C