CVE-2026-69641
Microsoft Exchange Server missing authorization allows privilege elevation (CVE-2026-69641)
Microsoft Exchange Server has a missing authorization vulnerability (CVE-2026-69641). An authenticated attacker with high privileges can elevate over the network. Fixed security updates are available; apply the builds listed. CVSS 9.1.
What happened
Microsoft Exchange Server has a missing authorization check (CWE-862). An attacker who already has high privileges can exploit this over a network to gain additional privileges, with no user interaction required. The CVSS 3.1 vector describes low attack complexity, changed scope, and high impact to confidentiality, integrity and availability.
Microsoft rates this issue Important; the CVSS 3.1 base score is 9.1. Microsoft has not said whether this is being exploited, and the CVE record does not record public disclosure.
Who is affected
The following Microsoft Exchange Server builds are affected. If you run Exchange Server 2016 CU23, Exchange Server 2019 CU14 or CU15, or Exchange Server Subscription Edition RTM, check the exact build number.
- Microsoft Exchange Server 2016 Cumulative Update 23: versions 15.01.0.0 to before 15.01.2507.073
- Microsoft Exchange Server 2019 Cumulative Update 14: versions 15.02.0.0 to before 15.02.1544.046
- Microsoft Exchange Server 2019 Cumulative Update 15: versions 15.02.0.0 to before 15.02.1748.051
- Microsoft Exchange Server Subscription Edition RTM: versions 15.02.0.0 to before 15.02.2562.049
What to do now
- Apply the security update for your branch:
- Exchange Server 2016 CU23: 15.01.2507.073 (KB5121611)
- Exchange Server 2019 CU14: 15.02.1544.046 (KB5121610)
- Exchange Server 2019 CU15: 15.02.1748.051 (KB5121609)
- Exchange Server Subscription Edition RTM: 15.02.2562.049 (KB5121608)
- Microsoft has not published workarounds for this vulnerability. If you cannot patch immediately, restrict administrative access to Exchange to trusted networks and monitor for unexpected privileged-role changes until the update is applied.
Beyond the patch
Beyond applying this update, this is a reminder that privilege escalation in a core messaging platform is exactly the kind of activity that leaves traces in logs and endpoint telemetry. Managed Detection & Response (MDR) watches for that post-compromise movement, while Supply Chain Defense & Third-Party Risk helps track patch exposure across the Microsoft estate—and the many other suppliers whose update cycles create the same risk.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Microsoft Exchange Server 2016 Cumulative Update 23 | 15.01.0.0 – < 15.01.2507.073 | 15.01.2507.073 |
| Microsoft Exchange Server 2019 Cumulative Update 14 | 15.02.0.0 – < 15.02.1544.046 | 15.02.1544.046 |
| Microsoft Exchange Server 2019 Cumulative Update 15 | 15.02.0.0 – < 15.02.1748.051 | 15.02.1748.051 |
| Microsoft Exchange Server Subscription Edition RTM | 15.02.0.0 – < 15.02.2562.049 | 15.02.2562.049 |