CVE-2026-21527
Microsoft Exchange Server SE vulnerability analysis and mitigation

Overview

CVE-2026-21527 is an SMTP header spoofing vulnerability in Microsoft Exchange Server that allows unauthenticated remote attackers to bypass a security feature by exploiting improper handling of SMTP headers within the InterceptorSmtpAgent class. Disclosed on February 10, 2026, as part of Microsoft's Patch Tuesday release, it affects Exchange Server 2016 (Cumulative Update 23), Exchange Server 2019 (Cumulative Update 14 and 15), and Exchange Server Subscription Edition (versions prior to 15.02.2562.037) (Microsoft MSRC, Feedly). It carries a CVSS v3.1 base score of 6.5 (Medium), with no authentication required and network-level access (Feedly).

Technical details

The root cause lies in insufficient verification of data authenticity (CWE-345), UI misrepresentation of critical information (CWE-451), and improper validation of syntactic correctness of input (CWE-1286) within the InterceptorSmtpAgent class of Microsoft Exchange Server (Feedly). An attacker can craft malicious SMTP messages with manipulated headers that bypass Exchange's security inspection logic, causing the server to misrepresent the sender identity to recipients. No authentication, user interaction, or special privileges are required — the attack is conducted entirely over the network. Zero Day Initiative published two advisories (ZDI-26-082 and ZDI-26-194) providing additional technical context (ZDI Advisory 082, ZDI Advisory 194).

Impact

Successful exploitation allows an attacker to impersonate legitimate email senders, enabling large-scale phishing and credential theft campaigns targeting Exchange users. The vulnerability results in low confidentiality impact and low integrity impact, with no availability impact — attackers can manipulate how email metadata is presented to recipients without disrupting mail flow (Feedly). While the direct technical impact is moderate, the practical risk is significant given that spoofed emails from trusted internal or external senders can be used to harvest credentials, distribute malware, or conduct business email compromise (BEC) attacks at scale.

Exploitation steps

  1. Reconnaissance: Identify internet-facing Microsoft Exchange Server instances (versions 2016 CU23, 2019 CU14/CU15, or Subscription Edition prior to 15.02.2562.037) using tools like Shodan, Censys, or MXToolbox to enumerate mail servers.
  2. Craft malicious SMTP message: Construct an email with manipulated SMTP headers (e.g., From, Sender, or related headers) that exploit the improper validation logic in the InterceptorSmtpAgent class to bypass Exchange's header inspection.
  3. Send spoofed email: Deliver the crafted SMTP message directly to the target Exchange server over port 25 (SMTP) without requiring any authentication, leveraging the network-accessible nature of the flaw.
  4. Bypass security feature: The malformed headers cause Exchange to misrepresent the sender identity to the recipient, making the email appear to originate from a trusted or legitimate sender.
  5. Achieve objective: Use the spoofed email to conduct phishing, credential harvesting, or business email compromise (BEC) attacks against Exchange users who trust the apparent sender identity (ZDI Advisory 082, Feedly).

Indicators of compromise

  • Network: Unexpected SMTP connections from external or unknown IP addresses delivering messages with anomalous or malformed header structures; inbound SMTP traffic with mismatched From, Sender, Return-Path, or Reply-To headers that bypass normal anti-spoofing checks.
  • Logs: Exchange transport logs (SMTP Receive logs) showing messages accepted with unusual or syntactically malformed SMTP headers; messages passing through InterceptorSmtpAgent without expected header validation rejections; increased volume of inbound mail from previously unseen sending IPs claiming to be internal or trusted domains.
  • Email Artifacts: Delivered emails where the displayed sender does not match the actual envelope sender (MAIL FROM); emails that bypass SPF, DKIM, or DMARC checks due to header manipulation; messages with duplicate or conflicting From header fields.

Mitigation and workarounds

Microsoft released security updates on February 10, 2026 to address this vulnerability. Administrators should apply the relevant update for their Exchange version: Exchange Server 2016 CU23 with the February 2026 Security Update, Exchange Server 2019 CU14 or CU15 with the February 2026 Security Update, and Exchange Server Subscription Edition updated to version 15.02.2562.037 or later (Microsoft MSRC). As supplementary defenses, organizations should implement or enforce email authentication controls — SPF, DKIM, and DMARC — to reduce the effectiveness of spoofing attacks, and monitor SMTP logs for suspicious header manipulation patterns (Feedly). Given the availability of public PoC exploits and the unauthenticated, network-accessible nature of this vulnerability, patching should be prioritized.

Community reactions

The vulnerability was covered as part of broader February 2026 Patch Tuesday reporting by multiple security outlets including BleepingComputer, GBHackers, Rapid7, Qualys, and Sophos, though it was not among the most prominently highlighted issues in that release cycle (BleepingComputer, Rapid7, Sophos). Qualys and Rapid7 included it in their Patch Tuesday review blogs, noting the unauthenticated network attack vector as a concern (Qualys Blog). The SANS Internet Storm Center also referenced the vulnerability in its February 2026 diary entry (SANS ISC).

Additional resources


SourceThis report was generated using AI

Related Microsoft Exchange Server SE vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45504HIGH8.8
  • Microsoft Exchange Server SE logoMicrosoft Exchange Server SE
  • cpe:2.3:a:microsoft:exchange_server:*:*:*:*:subscription:*:*:*
NoYesJun 09, 2026
CVE-2026-21527MEDIUM6.5
  • Microsoft Exchange Server SE logoMicrosoft Exchange Server SE
  • cpe:2.3:a:microsoft:exchange_server:*:*:*:*:subscription:*:*:*
NoYesFeb 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management