VORANT. Threat Intelligence Sign in Get the full feed

Microsoft Patches Nine Critical Exchange Server Flaws

routine vulnerability technology

Microsoft fixed nine Exchange Server vulnerabilities, including a CVSS 9.9 flaw letting authenticated attackers hijack any mailbox.

NCSC-NL published an advisory detailing nine vulnerabilities patched by Microsoft in Exchange Server, covering weaknesses such as SSRF, XSS, double-free, broken cryptography, uncontrolled recursion, and multiple authorization-bypass issues. The most severe, CVE-2026-69380 (CVSS 9.9), allows a low-privileged authenticated user with a mailbox to escalate privileges over the network and impersonate other users, enabling full mailbox takeover, reading/sending email, and downloading attachments. CVE-2026-69356 (CVSS 9.3) is an unauthenticated cross-site scripting flaw triggered via a crafted calendar invite; if a victim opens the meeting link in Outlook on the Web, the attacker can execute scripts within the session and view or modify mailbox data. CVE-2026-69641 (CVSS 9.1) lets a highly privileged authenticated attacker bypass mailbox authorization checks via a crafted request to access other users' mailboxes.

Six additional CVEs round out the set, ranging from remote code execution (CVE-2026-55007, CVE-2026-69355) to denial-of-service (CVE-2026-69378), impersonation (CVE-2026-69361), tampering (CVE-2026-69375), and sensitive data exposure (CVE-2026-69382), with CVSS scores from 5.9 to 8.8. No evidence of active in-the-wild exploitation is mentioned in the advisory; this is a coordinated patch release. Defenders running on-premises Exchange Server should prioritize applying Microsoft's updates immediately given the severity and mailbox-takeover potential of the top-tier flaws, monitor for anomalous mailbox access/impersonation patterns, and review Outlook on the Web calendar invite handling for suspicious script execution attempts.

Mentioned in this report

Vulnerabilities CVE-2026-55007CVE-2026-69355CVE-2026-69356CVE-2026-69361CVE-2026-69375CVE-2026-69378CVE-2026-69380CVE-2026-69382CVE-2026-69641

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0349.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free