Summary
A deserialization of untrusted data vulnerability in Microsoft Exchange Server allows any user with a mailbox account to crash the server repeatedly, causing sustained denial of service across the entire organization. The only prerequisite is a valid email account on the target Exchange server — no administrative privileges or special roles are required.
The vulnerability was reported as a denial of service; however, the underlying deserialization primitive may carry remote code execution potential given the right gadget chain. No RCE gadget was identified during our research.
This vulnerability was discovered by Aretiq AI and responsibly disclosed to Microsoft, who addressed it in the August 2026 Patch Tuesday security updates. Microsoft has credited ECooper with Aretiq.AI for reporting this vulnerability in their security advisory.
Affected Versions
| Product | Vulnerable Versions | Fixed Build | Patch |
|---|---|---|---|
| Exchange Server 2016 CU23 | < 15.01.2507.072 | 15.01.2507.072 | KB5121576 |
| Exchange Server 2019 CU14 | < 15.02.1544.044 | 15.02.1544.044 | KB5121575 |
| Exchange Server 2019 CU15 | < 15.02.1748.049 | 15.02.1748.049 | KB5121574 |
| Exchange Server SE RTM | < 15.02.2562.046 | 15.02.2562.046 | KB5121573 |
Remediation
Apply the corresponding security update for your Exchange Server version. All patches require a server restart.
Timeline
| Date | Event |
|---|---|
| 2026-05-26 | Vulnerability reported to Microsoft |
| 2026-06-23 | Microsoft confirms vulnerability impact |
| 2026-07-29 | Microsoft acknowledges patch release date |
| 2026-08-11 | Microsoft releases security update (August 2026 Patch Tuesday) |
| 2026-08-11 | Advisory published |