Skip to content

CVE-2026-69641

Microsoft Exchange Server missing authorization allows privilege elevation (CVE-2026-69641)

Critical 9.1 Vendor: Microsoft Published

Microsoft Exchange Server has a missing authorization vulnerability (CVE-2026-69641). An authenticated attacker with high privileges can elevate over the network. Fixed security updates are available; apply the builds listed. CVSS 9.1.

What happened

Microsoft Exchange Server has a missing authorization check (CWE-862). An attacker who already has high privileges can exploit this over a network to gain additional privileges, with no user interaction required. The CVSS 3.1 vector describes low attack complexity, changed scope, and high impact to confidentiality, integrity and availability.

Microsoft rates this issue Important; the CVSS 3.1 base score is 9.1. Microsoft has not said whether this is being exploited, and the CVE record does not record public disclosure.

Who is affected

The following Microsoft Exchange Server builds are affected. If you run Exchange Server 2016 CU23, Exchange Server 2019 CU14 or CU15, or Exchange Server Subscription Edition RTM, check the exact build number.

  • Microsoft Exchange Server 2016 Cumulative Update 23: versions 15.01.0.0 to before 15.01.2507.073
  • Microsoft Exchange Server 2019 Cumulative Update 14: versions 15.02.0.0 to before 15.02.1544.046
  • Microsoft Exchange Server 2019 Cumulative Update 15: versions 15.02.0.0 to before 15.02.1748.051
  • Microsoft Exchange Server Subscription Edition RTM: versions 15.02.0.0 to before 15.02.2562.049

What to do now

  1. Apply the security update for your branch:
  • Exchange Server 2016 CU23: 15.01.2507.073 (KB5121611)
  • Exchange Server 2019 CU14: 15.02.1544.046 (KB5121610)
  • Exchange Server 2019 CU15: 15.02.1748.051 (KB5121609)
  • Exchange Server Subscription Edition RTM: 15.02.2562.049 (KB5121608)
  1. Microsoft has not published workarounds for this vulnerability. If you cannot patch immediately, restrict administrative access to Exchange to trusted networks and monitor for unexpected privileged-role changes until the update is applied.

Beyond the patch

Beyond applying this update, this is a reminder that privilege escalation in a core messaging platform is exactly the kind of activity that leaves traces in logs and endpoint telemetry. Managed Detection & Response (MDR) watches for that post-compromise movement, while Supply Chain Defense & Third-Party Risk helps track patch exposure across the Microsoft estate—and the many other suppliers whose update cycles create the same risk.

Affected and fixed versions

ProductAffectedFixed in
Microsoft Exchange Server 2016 Cumulative Update 2315.01.0.0 – < 15.01.2507.07315.01.2507.073
Microsoft Exchange Server 2019 Cumulative Update 1415.02.0.0 – < 15.02.1544.04615.02.1544.046
Microsoft Exchange Server 2019 Cumulative Update 1515.02.0.0 – < 15.02.1748.05115.02.1748.051
Microsoft Exchange Server Subscription Edition RTM15.02.0.0 – < 15.02.2562.04915.02.2562.049

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.