Status: UPDATED | Advisory ID: CVE-2026-69641
| CVE | CVE-2026-69641 |
| CVSS Score / Version | 9.1 (Critical) / CVSS v3.1 |
| Updated | 2026-09-22 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is high; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Microsoft Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Microsoft Exchange Server Subscription Edition RTM, and Microsoft exchange_server_subscription_edition |
| Classified as | CWE-862 (Missing Authorization) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | ||
| Microsoft | Microsoft Exchange Server 2019 Cumulative Update 14 | ||
| Microsoft | Microsoft Exchange Server 2019 Cumulative Update 15 | ||
| Microsoft | Microsoft Exchange Server Subscription Edition RTM | ||
| Microsoft | exchange_server_subscription_edition |
| Subsystems | General OT |
| Sectors | Multiple |
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Monitor Microsoft's web page for any future patch releases. See vendor advisory link below.