CVE-2026-69378
Microsoft · Published September 8, 2026
7.5
CVSS v3.1
HIGHPatch availableGet patch
Description
Microsoft Exchange Server Denial of Service Vulnerability. Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.
Affected Products
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Update 14
- Microsoft Exchange Server Subscription Edition RTM
- Microsoft Exchange Server 2019 Cumulative Update 15
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C