Assessment
Why it matters
KEV inclusion, a public exploit and high exploitation probability combine with the privileged position of mail infrastructure.
Who should care
- Exchange administrators
- Security operations teams
- Organisations with on-premises mail services
Response plan
What I would do
- Inventory affected Exchange builds.
- Prioritise internet-facing servers.
- Apply the security update.
- Run the vendor health and compromise checks.
- Review authentication and process telemetry.
Technical details
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-502: Deserialization of Untrusted Data
- Affected versions
- Demonstration range: selected supported Exchange Server builds
- Published
- 16 Aug 2026
- Attack vector
- Network
- Privileges required
- None
- User interaction
- None
Signal timeline
- Security update published
- Public exploit reported
- KEV status added
- Signal increased to 89