CVE-2026-69355: Microsoft Exchange Server Remote Code Execution Vulnerability
Published Sep 8, 2026
·Updated
External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
Other sources
Microsoft Exchange Server Remote Code Execution Vulnerability
— Microsoft
Affected Software
1 affected component
Microsoft Exchange Server
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
CVE Published
via MITRE·05:12 PM
Data Sourced
via MITRE·05:12 PM
DescriptionSeverity
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does an attacker need an existing account or permissions to exploit this issue?
Yes. The vulnerability is rated PR:L, indicating that the attacker must have low-level privileges or authorization before exploitation.
2
Can this be exploited remotely without user interaction?
The CVSS vector lists AV:N and UI:N, indicating network-based exploitation without user interaction. Attack complexity is rated low (AC:L).
3
What is the potential impact of a successful exploit?
Successful exploitation can result in high impact to confidentiality, integrity, and availability, as reflected by C:H, I:H, and A:H in the CVSS vector.