Description
External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

External control of a file name or path in the Exchange Server allows an attacker who has authorized access to the system to execute arbitrary code over the network. The vulnerability, identified as CWE-73, permits remote code execution which can lead to full system compromise, data exfiltration or alteration.

Affected Systems

Microsoft Exchange Server 2016 cumulative update 23, Microsoft Exchange Server 2019 cumulative update 14 and 15, and Microsoft Exchange Server Subscription Edition RTM are affected. These versions must be identified and updated accordingly.

Risk and Exploitability

The CVSS score of 8.8 classifies this as a high severity vulnerability. While an EPSS score is not available, the fact that the vulnerability is not listed in CISA’s KEV means no large-scale exploitation has yet been observed, but the high CVSS indicates significant risk. The likely attack vector is a network-based exploitation that leverages an authenticated session with sufficient privileges to manipulate the file name or path.

Generated by OpenCVE AI on September 8, 2026 at 22:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest cumulative update for your Exchange Server version: Exchange 2016 CU23, Exchange 2019 CU14 or CU15, and the current Subscription Edition RTM update. This is the official fix provided by Microsoft.
  • Restart all Exchange services after the update to ensure the patch is fully applied.
  • If immediate patching is not possible, restrict the Exchange server’s exposure to network traffic by limiting administrative access to trusted IP ranges or implementing firewall rules that block untrusted connections until the update is installed.

Generated by OpenCVE AI on September 8, 2026 at 22:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Exchange Server 2019 Cumulative Update 15
Vendors & Products Microsoft microsoft Exchange Server 2019 Cumulative Update 15

Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
Title Microsoft Exchange Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft exchange Server 2016
Microsoft exchange Server 2019
Microsoft exchange Server Se
Weaknesses CWE-73
CPEs cpe:2.3:a:microsoft:exchange_server_2016:*:cumulative_update_23:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_14:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_15:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_se:*:RTM:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft exchange Server 2016
Microsoft exchange Server 2019
Microsoft exchange Server Se
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Exchange Server 2016 Exchange Server 2019 Exchange Server Se Microsoft Exchange Server 2019 Cumulative Update 15
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:32:40.835Z

Reserved: 2026-08-03T20:52:08.512Z

Link: CVE-2026-69355

cve-icon Vulnrichment

Updated: 2026-09-09T10:01:47.358Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:18:54.910

Modified: 2026-09-09T10:18:10.857

Link: CVE-2026-69355

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T14:45:17Z

Weaknesses
  • CWE-73

    External Control of File Name or Path