CVE-2026-21527: Microsoft Exchange Server Spoofing Vulnerability
Published Feb 10, 2026
·Updated
Microsoft Exchange Server Spoofing Vulnerability
Other sources
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
— Microsoft
Affected Software
7 affected componentsFixes available
Microsoft Exchange Server 2019=15
Microsoft Exchange Server Subscription Edition RTM
Microsoft Exchange Server 2016=23
Microsoft Exchange Server=2016-cumulative_update_23
Microsoft Exchange Server=2019-cumulative_update_14
Microsoft Exchange Server=2019-cumulative_update_15
Microsoft Exchange Server Subscription Edition<15.02.2562.037
Event History
Feb 10, 2026
CVE Published
via Microsoft·04:00 PM
Data Sourced
via Microsoft·04:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·04:00 PM
Affected Software
Updated
via Microsoft·04:00 PM
Affected Software
Updated
via Microsoft·04:00 PM
Description
CVE Published
via MITRE·05:51 PM
Data Sourced
via MITRE·05:51 PM
DescriptionSeverity
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-21527?
CVE-2026-21527 is a critical spoofing vulnerability in Microsoft Exchange Server.
2
How do I fix CVE-2026-21527?
To fix CVE-2026-21527, apply the patches provided in Microsoft's support updates for the affected Exchange Server versions.
3
Which versions of Microsoft Exchange Server are affected by CVE-2026-21527?
CVE-2026-21527 affects Microsoft Exchange Server 2016, 2019, and Subscription Edition.
4
What type of attack does CVE-2026-21527 facilitate?
CVE-2026-21527 allows an unauthorized attacker to perform spoofing attacks over a network.
5
How can I determine if my Exchange Server version is vulnerable to CVE-2026-21527?
Check the version number of your Microsoft Exchange Server against the affected versions listed in the CVE description.