Description
Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply patch
AI Analysis

Impact

A flaw in the cryptographic algorithm used by Microsoft Exchange Server permits an attacker who is not authenticated to disclose sensitive information over a network. The vulnerability is caused by a broken or risky cryptographic implementation that can be triggered from an external connection.

Affected Systems

Microsoft Exchange Server 2016 with Cumulative Update 23, Exchange Server 2019 with Cumulative Updates 14 and 15, and Exchange Server Subscription Edition RTM are specified as affected. Systems running these update levels are impacted unless a newer update is installed or an alternative mitigation is applied.

Risk and Exploitability

The vulnerability has a CVSS score of 5.9, indicating moderate severity. No EPSS score is available and it is not listed in the CISA KEV catalog. Attackers can exploit the issue from a network location without authentication by interacting with Exchange services to trigger the information disclosure, but the CVE description does not provide further exploitation details.

Generated by OpenCVE AI on September 8, 2026 at 22:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest cumulative updates for Exchange Server 2016, 2019, and the Subscription Edition as provided by Microsoft
  • Disable or remove any deprecated cryptographic algorithms from the Exchange configuration
  • Monitor Exchange logs and network traffic for signs of unauthorized data disclosure

Generated by OpenCVE AI on September 8, 2026 at 22:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Exchange Server 2016 Cumulative Update 23
Microsoft microsoft Exchange Server 2019 Cumulative Update 14
Microsoft microsoft Exchange Server 2019 Cumulative Update 15
Microsoft microsoft Exchange Server Subscription Edition Rtm
Vendors & Products Microsoft microsoft Exchange Server 2016 Cumulative Update 23
Microsoft microsoft Exchange Server 2019 Cumulative Update 14
Microsoft microsoft Exchange Server 2019 Cumulative Update 15
Microsoft microsoft Exchange Server Subscription Edition Rtm

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
Title Microsoft Exchange Server Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft exchange Server 2016
Microsoft exchange Server 2019
Microsoft exchange Server Se
Weaknesses CWE-327
CPEs cpe:2.3:a:microsoft:exchange_server_2016:*:cumulative_update_23:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_14:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_15:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_se:*:RTM:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft exchange Server 2016
Microsoft exchange Server 2019
Microsoft exchange Server Se
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Exchange Server 2016 Exchange Server 2019 Exchange Server Se Microsoft Exchange Server 2016 Cumulative Update 23 Microsoft Exchange Server 2019 Cumulative Update 14 Microsoft Exchange Server 2019 Cumulative Update 15 Microsoft Exchange Server Subscription Edition Rtm
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:32:44.491Z

Reserved: 2026-08-03T20:54:04.487Z

Link: CVE-2026-69382

cve-icon Vulnrichment

Updated: 2026-09-08T20:23:02.352Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:18:59.110

Modified: 2026-09-08T21:18:31.340

Link: CVE-2026-69382

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T21:45:14Z

Weaknesses
  • CWE-327

    Use of a Broken or Risky Cryptographic Algorithm