ZDI-26-194: Microsoft Exchange InterceptorSmtpAgent Improper Input Validation Security Feature Bypass Vulnerability
Published Mar 16, 2026
·Updated
This vulnerability allows remote attackers to bypass a security feature on affected installations of Microsoft Exchange. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2026-21527.
Affected Software
1 affected component
Microsoft Exchange
Event History
Mar 16, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-26-194?
ZDI-26-194 is classified as a medium severity vulnerability.
2
How do I fix ZDI-26-194?
To remediate ZDI-26-194, apply security updates provided by Microsoft for affected versions of Exchange.
3
Who is affected by ZDI-26-194?
ZDI-26-194 affects installations of Microsoft Exchange that utilize the InterceptorSmtpAgent.
4
Can ZDI-26-194 be exploited without authentication?
Yes, ZDI-26-194 can be exploited without requiring authentication.
5
What is the nature of the vulnerability in ZDI-26-194?
ZDI-26-194 involves improper input validation that allows security feature bypass.