CVE-2026-55005: Microsoft Exchange Server Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
Other sources
Microsoft Exchange Server Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1748.048Patch KB5103213 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.2562.045Patch KB5103212 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2507.071Patch KB5103215 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1544.043Patch KB5103214
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55005?
CVE-2026-55005 has a high severity rating of 8.8.
How can I fix CVE-2026-55005?
To fix CVE-2026-55005, apply the latest updates and patches provided by Microsoft for Exchange Server.
What systems are affected by CVE-2026-55005?
CVE-2026-55005 affects Microsoft Exchange Server 2019, Microsoft Exchange Server Subscription Edition RTM, and Microsoft Exchange Server 2016.
What type of vulnerability is CVE-2026-55005?
CVE-2026-55005 is classified as a heap-based buffer overflow vulnerability.
What can an attacker achieve by exploiting CVE-2026-55005?
An authorized attacker can execute arbitrary code over a network by exploiting CVE-2026-55005.