Description
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
Published: 2026-07-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a heap-based buffer overflow in Microsoft Exchange Server that permits an authorized attacker to execute code on the server from the network. The flaw enables full control of the affected system, potentially compromising confidential data, integrity, and availability. Based on the description, it is inferred that the overflow is triggered by sending maliciously crafted input over the network.

Affected Systems

The affected systems are Microsoft Exchange Server 2016 running Cumulative Update 23, Microsoft Exchange Server 2019 running Cumulative Update 14 or 15, and Microsoft Exchange Server Subscription Edition in its RTM configuration. All instances running these specific updates are vulnerable; earlier or later releases are not affected.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, while the EPSS score of <1% shows that this flaw is not heavily exploited at present. The vulnerability is not listed in the CISA KEV catalog, suggesting that it has not been observed in the wild. The likely attack vector is an authorized user on the network sending maliciously crafted requests, based on the description. Because the attack requires only authorized credentials, malicious insiders or compromised service accounts could exploit it, leading to a complete loss of confidentiality, integrity, and availability if successful.

Generated by OpenCVE AI on July 31, 2026 at 09:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft Exchange Server Cumulative Update 23 for Exchange Server 2016, or Cumulative Update 14/15 for Exchange Server 2019, and the latest security update for Exchange Server Subscription Edition RTM.
  • Restrict network exposure by disabling unused services and limiting inbound connections to only essential ports.
  • Conduct regular security scans and monitor logs for suspicious activity to confirm that the vulnerability has been fully mitigated.

Generated by OpenCVE AI on July 31, 2026 at 09:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
Title Microsoft Exchange Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft exchange Server 2016
Microsoft exchange Server 2019
Microsoft exchange Server Se
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:exchange_server_2016:*:cumulative_update_23:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_14:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_15:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_se:*:RTM:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft exchange Server 2016
Microsoft exchange Server 2019
Microsoft exchange Server Se
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Exchange Server 2016 Exchange Server 2019 Exchange Server Se
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:22:37.501Z

Reserved: 2026-06-16T14:10:05.869Z

Link: CVE-2026-55005

cve-icon Vulnrichment

Updated: 2026-07-15T10:59:12.695Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:30:05Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow