Skip to content
Weekly Signal
Demonstration intelligence Updated 17 Aug 2026 · 18:42 UTC

Microsoft · Exchange Server

CVE-2026-23108

Remote code execution affecting exposed mail infrastructure

Recommended action

Patch supported Exchange Server deployments promptly and review internet-facing services for signs of exploitation.

View response plan
CVSS8.8
EPSS91.7%
KEVYes
ExploitationPublic exploit
PatchAvailable

Assessment

Why it matters

KEV inclusion, a public exploit and high exploitation probability combine with the privileged position of mail infrastructure.

Who should care

  • Exchange administrators
  • Security operations teams
  • Organisations with on-premises mail services

Response plan

What I would do

  1. Inventory affected Exchange builds.
  2. Prioritise internet-facing servers.
  3. Apply the security update.
  4. Run the vendor health and compromise checks.
  5. Review authentication and process telemetry.

Technical details

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-502: Deserialization of Untrusted Data
Affected versions
Demonstration range: selected supported Exchange Server builds
Published
16 Aug 2026
Attack vector
Network
Privileges required
None
User interaction
None

Signal timeline

  1. Security update published
  2. Public exploit reported
  3. KEV status added
  4. Signal increased to 89
Demonstration data This page shows the intended product experience using fictional CVE records. Dates, evidence, affected versions and recommendations must not be used as live security advice.