PT-2026-7408 · Microsoft · Exchange Server

Vladislav Berghici

·

Published

2026-02-10

·

Updated

2026-03-16

·

CVE-2026-21527

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Exchange Server (affected versions not specified)
Description A flaw in Microsoft Exchange Server’s user interface can lead to the misrepresentation of critical information. This allows an unauthorized attacker to conduct spoofing attacks over a network. The issue enables attackers to affect the system through spoofing.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Verification of Data Authenticity

UI Misrepresentation of Critical Information

Weakness Enumeration

Related Identifiers

BDU:2026-01812
CVE-2026-21527
ZDI-26-082
ZDI-26-194

Affected Products

Exchange Server