Advisory Details

March 16th, 2026

Microsoft Exchange InterceptorSmtpAgent Improper Input Validation Security Feature Bypass Vulnerability

ZDI-26-194
ZDI-CAN-28462

CVE ID CVE-2026-21527
CVSS SCORE 5.3, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
AFFECTED VENDORS Microsoft
AFFECTED PRODUCTS Exchange
VULNERABILITY DETAILS

This vulnerability allows remote attackers to bypass a security feature on affected installations of Microsoft Exchange. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the InterceptorSmtpAgent class. The issue results from the improper parsing of SMTP headers. An attacker can leverage this vulnerability to bypass a security feature offered by the product.

ADDITIONAL DETAILS Microsoft has issued an update to correct this vulnerability. More details can be found at:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21527
DISCLOSURE TIMELINE
  • 2025-11-14 - Vulnerability reported to vendor
  • 2026-03-16 - Coordinated public release of advisory
  • 2026-03-16 - Advisory Updated
CREDIT Vladislav Berghici of Trend Research
BACK TO ADVISORIES