Summary

A deserialization of untrusted data vulnerability in Microsoft Exchange Server allows any user with a mailbox account to crash the server repeatedly, causing sustained denial of service across the entire organization. The only prerequisite is a valid email account on the target Exchange server — no administrative privileges or special roles are required.

The vulnerability was reported as a denial of service; however, the underlying deserialization primitive may carry remote code execution potential given the right gadget chain. No RCE gadget was identified during our research.

This vulnerability was discovered by Aretiq AI and responsibly disclosed to Microsoft, who addressed it in the August 2026 Patch Tuesday security updates. Microsoft has credited ECooper with Aretiq.AI for reporting this vulnerability in their security advisory.

Affected Versions

ProductVulnerable VersionsFixed BuildPatch
Exchange Server 2016 CU23< 15.01.2507.07215.01.2507.072KB5121576
Exchange Server 2019 CU14< 15.02.1544.04415.02.1544.044KB5121575
Exchange Server 2019 CU15< 15.02.1748.04915.02.1748.049KB5121574
Exchange Server SE RTM< 15.02.2562.04615.02.2562.046KB5121573

Remediation

Apply the corresponding security update for your Exchange Server version. All patches require a server restart.

Timeline

DateEvent
2026-05-26Vulnerability reported to Microsoft
2026-06-23Microsoft confirms vulnerability impact
2026-07-29Microsoft acknowledges patch release date
2026-08-11Microsoft releases security update (August 2026 Patch Tuesday)
2026-08-11Advisory published

References