CVE-2026-69378: Microsoft Exchange Server Denial of Service Vulnerability
Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2507.073Patch KB5121611 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1544.046Patch KB5121610 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1748.051Patch KB5121609 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.2562.049Patch KB5121608
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The vector indicates network-based exploitation with low attack complexity. It does not require privileges or user interaction.
What security impact is indicated?
The reported impact is limited to availability, with no confidentiality or integrity impact indicated. The scope is unchanged.
Which Exchange Server releases are listed as affected?
Microsoft Exchange Server 2016, Microsoft Exchange Server 2019, and Microsoft Exchange Server Subscription Edition RTM are listed.