# Microsoft Patches Nine Critical Exchange Server Flaws

Published: 2026-09-08 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/881b112b-4ed9-50f2-9859-951e98bcdb19/microsoft-patches-nine-critical-exchange-server-flaws

> Microsoft fixed nine Exchange Server vulnerabilities, including a CVSS 9.9 flaw letting authenticated attackers hijack any mailbox.

NCSC-NL published an advisory detailing nine vulnerabilities patched by Microsoft in Exchange Server, covering weaknesses such as SSRF, XSS, double-free, broken cryptography, uncontrolled recursion, and multiple authorization-bypass issues. The most severe, CVE-2026-69380 (CVSS 9.9), allows a low-privileged authenticated user with a mailbox to escalate privileges over the network and impersonate other users, enabling full mailbox takeover, reading/sending email, and downloading attachments. CVE-2026-69356 (CVSS 9.3) is an unauthenticated cross-site scripting flaw triggered via a crafted calendar invite; if a victim opens the meeting link in Outlook on the Web, the attacker can execute scripts within the session and view or modify mailbox data. CVE-2026-69641 (CVSS 9.1) lets a highly privileged authenticated attacker bypass mailbox authorization checks via a crafted request to access other users' mailboxes.

Six additional CVEs round out the set, ranging from remote code execution (CVE-2026-55007, CVE-2026-69355) to denial-of-service (CVE-2026-69378), impersonation (CVE-2026-69361), tampering (CVE-2026-69375), and sensitive data exposure (CVE-2026-69382), with CVSS scores from 5.9 to 8.8. No evidence of active in-the-wild exploitation is mentioned in the advisory; this is a coordinated patch release. Defenders running on-premises Exchange Server should prioritize applying Microsoft's updates immediately given the severity and mailbox-takeover potential of the top-tier flaws, monitor for anomalous mailbox access/impersonation patterns, and review Outlook on the Web calendar invite handling for suspicious script execution attempts.

## Mentioned in this report

- Vulnerabilities: CVE-2026-55007, CVE-2026-69355, CVE-2026-69356, CVE-2026-69361, CVE-2026-69375, CVE-2026-69378, CVE-2026-69380, CVE-2026-69382, CVE-2026-69641

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0349.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/881b112b-4ed9-50f2-9859-951e98bcdb19/microsoft-patches-nine-critical-exchange-server-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
