Skip to main content

Microsoft Exchange Server Unauthenticated Network Remote Code Execution via Double-Free Vulnerability (CVE-2026-55007)

Scope: Microsoft Exchange Server (All Supported On-Premises Versions Prior to September 2026 Cumulative Update)

Severity: High

CVE-2026-55007 (CVSS 8.1) is a double-free memory corruption vulnerability in Microsoft Exchange Server addressed in September's record-breaking Patch Tuesday, allowing unauthenticated remote attackers to execute arbitrary code over the network with no credentials and no user interaction required on any unpatched Exchange Server instance reachable via the network. Exchange Server is the foundational email platform across Ugandan government ministries, regulatory bodies, financial institutions, and large enterprise organizations, making any unpatched on-premises Exchange deployment an immediate and broad-surface risk. Although no exploitation in the wild has been confirmed at time of publication, the unauthenticated attack surface and network-reachable nature of the flaw mean exploitation tooling is likely to emerge rapidly given the consistent pattern of Exchange vulnerabilities being weaponized within days of public disclosure. Organizations must apply the September 2026 Exchange cumulative update immediately and restrict Exchange management interfaces to trusted IP ranges only.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.