
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21527 is an SMTP header spoofing vulnerability in Microsoft Exchange Server that allows unauthenticated remote attackers to bypass a security feature by exploiting improper handling of SMTP headers within the InterceptorSmtpAgent class. Disclosed on February 10, 2026, as part of Microsoft's Patch Tuesday release, it affects Exchange Server 2016 (Cumulative Update 23), Exchange Server 2019 (Cumulative Update 14 and 15), and Exchange Server Subscription Edition (versions prior to 15.02.2562.037) (Microsoft MSRC, Feedly). It carries a CVSS v3.1 base score of 6.5 (Medium), with no authentication required and network-level access (Feedly).
The root cause lies in insufficient verification of data authenticity (CWE-345), UI misrepresentation of critical information (CWE-451), and improper validation of syntactic correctness of input (CWE-1286) within the InterceptorSmtpAgent class of Microsoft Exchange Server (Feedly). An attacker can craft malicious SMTP messages with manipulated headers that bypass Exchange's security inspection logic, causing the server to misrepresent the sender identity to recipients. No authentication, user interaction, or special privileges are required — the attack is conducted entirely over the network. Zero Day Initiative published two advisories (ZDI-26-082 and ZDI-26-194) providing additional technical context (ZDI Advisory 082, ZDI Advisory 194).
Successful exploitation allows an attacker to impersonate legitimate email senders, enabling large-scale phishing and credential theft campaigns targeting Exchange users. The vulnerability results in low confidentiality impact and low integrity impact, with no availability impact — attackers can manipulate how email metadata is presented to recipients without disrupting mail flow (Feedly). While the direct technical impact is moderate, the practical risk is significant given that spoofed emails from trusted internal or external senders can be used to harvest credentials, distribute malware, or conduct business email compromise (BEC) attacks at scale.
From, Sender, or related headers) that exploit the improper validation logic in the InterceptorSmtpAgent class to bypass Exchange's header inspection.From, Sender, Return-Path, or Reply-To headers that bypass normal anti-spoofing checks.SMTP Receive logs) showing messages accepted with unusual or syntactically malformed SMTP headers; messages passing through InterceptorSmtpAgent without expected header validation rejections; increased volume of inbound mail from previously unseen sending IPs claiming to be internal or trusted domains.MAIL FROM); emails that bypass SPF, DKIM, or DMARC checks due to header manipulation; messages with duplicate or conflicting From header fields.Microsoft released security updates on February 10, 2026 to address this vulnerability. Administrators should apply the relevant update for their Exchange version: Exchange Server 2016 CU23 with the February 2026 Security Update, Exchange Server 2019 CU14 or CU15 with the February 2026 Security Update, and Exchange Server Subscription Edition updated to version 15.02.2562.037 or later (Microsoft MSRC). As supplementary defenses, organizations should implement or enforce email authentication controls — SPF, DKIM, and DMARC — to reduce the effectiveness of spoofing attacks, and monitor SMTP logs for suspicious header manipulation patterns (Feedly). Given the availability of public PoC exploits and the unauthenticated, network-accessible nature of this vulnerability, patching should be prioritized.
The vulnerability was covered as part of broader February 2026 Patch Tuesday reporting by multiple security outlets including BleepingComputer, GBHackers, Rapid7, Qualys, and Sophos, though it was not among the most prominently highlighted issues in that release cycle (BleepingComputer, Rapid7, Sophos). Qualys and Rapid7 included it in their Patch Tuesday review blogs, noting the unauthenticated network attack vector as a concern (Qualys Blog). The SANS Internet Storm Center also referenced the vulnerability in its February 2026 diary entry (SANS ISC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."