CVE-2026-21527: Microsoft Exchange Server Spoofing Vulnerability
Microsoft Exchange Server Spoofing Vulnerability
Other sources
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1748.043Patch KB5074993 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1544.039Patch KB5074994 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.2562.037Patch KB5074992 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2507.066Patch KB5074995
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21527?
CVE-2026-21527 is a critical spoofing vulnerability in Microsoft Exchange Server.
How do I fix CVE-2026-21527?
To fix CVE-2026-21527, apply the patches provided in Microsoft's support updates for the affected Exchange Server versions.
Which versions of Microsoft Exchange Server are affected by CVE-2026-21527?
CVE-2026-21527 affects Microsoft Exchange Server 2016, 2019, and Subscription Edition.
What type of attack does CVE-2026-21527 facilitate?
CVE-2026-21527 allows an unauthorized attacker to perform spoofing attacks over a network.
How can I determine if my Exchange Server version is vulnerable to CVE-2026-21527?
Check the version number of your Microsoft Exchange Server against the affected versions listed in the CVE description.