ZDI-CAN-28410: ZDI-26-082: Microsoft Exchange InterceptorSmtpAgent Reliance on Untrusted Inputs Security Feature Bypass Vulnerability
This vulnerability allows remote attackers to bypass a security feature on affected installations of Microsoft Exchange. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2026-21527.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28410?
The severity of ZDI-CAN-28410 is high due to the potential for remote attackers to bypass important security features without requiring authentication.
How do I fix ZDI-CAN-28410?
To fix ZDI-CAN-28410, install the latest security update provided by Microsoft for your version of Microsoft Exchange.
What could happen if ZDI-CAN-28410 is exploited?
If ZDI-CAN-28410 is exploited, attackers could gain unauthorized access to features and functions of Microsoft Exchange, potentially compromising sensitive information.
Which versions of Microsoft Exchange are affected by ZDI-CAN-28410?
ZDI-CAN-28410 affects multiple versions of Microsoft Exchange, and all installations should be reviewed for vulnerability.
Is authentication required to exploit ZDI-CAN-28410?
No, authentication is not required to exploit ZDI-CAN-28410, making it particularly severe.