Description
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a double‑free bug in Microsoft Exchange Server that allows an unauthorized attacker to execute arbitrary code via a network connection. The flaw arises when memory that has already been freed is accessed again, enabling exploitation through malicious crafted requests. This weakness is classified as CWE‑415.

Affected Systems

Affected versions include Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server 2019 Cumulative Update 15, and Microsoft Exchange Server Subscription Edition RTM. All instances of these builds that have not applied a subsequent security update remain vulnerable.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, and with no EPSS score available the likelihood of exploitation is uncertain but non‑zero. The vulnerability is not currently listed in CISA's KEV catalog, but the remote attack surface suggests it could be leveraged by attackers with network access. Based on the description, it is inferred that the likely attack vector is a network‑based request to the Exchange service, and the impact could be full remote code execution on the host.

Generated by OpenCVE AI on September 8, 2026 at 18:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft Exchange Server cumulative update that contains the fix for CVE-2026-55007 (for example, CU16 or the latest security release).
  • Deploy the update to all affected Exchange Server 2019 and Subscription Edition machines, ensuring that the patch version is installed.
  • Configure firewall or access controls to limit inbound traffic to the Exchange Server to trusted IP addresses, thereby reducing exposure until the patch is applied.

Generated by OpenCVE AI on September 8, 2026 at 18:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Exchange Server 2019 Cumulative Update 14
Microsoft microsoft Exchange Server 2019 Cumulative Update 15
Microsoft microsoft Exchange Server Subscription Edition Rtm
Vendors & Products Microsoft microsoft Exchange Server 2019 Cumulative Update 14
Microsoft microsoft Exchange Server 2019 Cumulative Update 15
Microsoft microsoft Exchange Server Subscription Edition Rtm

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
Title Microsoft Exchange Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft exchange Server 2019
Microsoft exchange Server Se
Weaknesses CWE-415
CPEs cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_14:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_15:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_se:*:RTM:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft exchange Server 2019
Microsoft exchange Server Se
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Exchange Server 2019 Exchange Server Se Microsoft Exchange Server 2019 Cumulative Update 14 Microsoft Exchange Server 2019 Cumulative Update 15 Microsoft Exchange Server Subscription Edition Rtm
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:30:34.294Z

Reserved: 2026-06-16T14:12:44.283Z

Link: CVE-2026-55007

cve-icon Vulnrichment

Updated: 2026-09-09T10:04:54.290Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:17:41.820

Modified: 2026-09-09T10:17:06.033

Link: CVE-2026-55007

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T19:45:04Z

Weaknesses