
September's Record Patch Tuesday Had Two Real Zero-Days. ZDI Ranked an Unexploited Exchange Bug Above Both.
CVE-2026-55007 lets an unauthenticated attacker execute code on Exchange Server just by sending an email with a malicious Visio attachment — no click, no Preview Pane. Microsoft rates the attack complexity "high"; ZDI's Dustin Childs called it the month's most important patch anyway.
CVE Tools6 min read
A double-free hiding in your inbox
On September 8, 2026, Microsoft shipped its largest Patch Tuesday on record — somewhere between 972 and 997 CVEs depending on how you count Chromium-derived entries. Two of those bugs are confirmed zero-days, already added to CISA's Known Exploited Vulnerabilities catalog. Neither is the one Zero Day Initiative's Dustin Childs told people to drop everything for. That distinction went to CVE-2026-55007, an Exchange Server bug with no public exploit, no KEV listing, and — as of this writing — no confirmed victim. Here's why a bug nobody has caught in the wild outranked two that are actively being used.
Scores as of September 20, 2026live record →
How the attack works
CVE-2026-55007 is a double-free (CWE-415) in on-premises Exchange Server. Per Microsoft's advisory, reachable through multiple outlets that quoted it directly: an unauthenticated attacker sends an email with a malicious Visio attachment to the server. The code path that triggers isn't the mail client — it's Exchange's own content-indexing engine, which parses the attachment as part of normal message handling. Nobody has to open the email. Nobody has to preview it. The double-free fires while the server is doing its job.
CVE-2026-55007 attack chain
- Attacker sends email with malicious Visio attachment
- Exchange receives and queues the message
- Content-indexing engine parses the Visio file
- Server under sustained memory pressure?
- No — allocation succeeds, double-free doesn't trigger
- Yes — double-free triggers (CWE-415)
- Remote code execution on the Exchange server
A remote, unauthenticated attacker could get code execution on an affected Exchange server just by sending an email with a malicious Visio attachment. The code execution occurs when the server processes the mail – no need even for the Preview Pane.
Ranked above two confirmed zero-days
The same Patch Tuesday fixed two vulnerabilities Microsoft confirms were already being exploited: CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack), both local elevation-of-privilege bugs, both added to CISA's KEV catalog with a September 22, 2026 deadline for federal agencies. Neither needs to reach across a network — both require an attacker who is already running code on the box. CVE-2026-55007 needs nothing but a mail server that accepts external email.
| CVE | CVSS 3.1 vector / score | Attack vector | Privileges required | Confirmed exploited? |
|---|---|---|---|---|
| CVE-2026-55007 (Exchange RCE) | AV:N/AC:H/PR:N/UI:N — 8.1 | Network (email) | None | Not confirmed, not in KEV |
| CVE-2026-85880 (Windows ALPC EoP) | AV:L/AC:L/PR:L/UI:N — 7.8 | Local | Low (already on the box) | Yes — KEV, FCEB deadline Sept 22 |
| CVE-2026-81963 (Windows Update Stack EoP) | AV:L/AC:L/PR:L/UI:N — 7.8 | Local | Low (already on the box) | Yes — KEV, FCEB deadline Sept 22 |
Two ways to read the same patch batch
- CVSS 8.1 — High, not Critical
- Attack complexity: High
- No public PoC, no Metasploit, no Nuclei template
- Not on CISA's KEV list
- Unauthenticated — no account, no foothold needed
- Zero-click — fires during mail processing, before Preview Pane
- One of nine Exchange bugs in the same cycle
- "The attacker only needs to get it right once"
Not the only Exchange bug this month
CVE-2026-55007 shipped alongside four more High- or Critical-rated Exchange Server fixes in the same release — none currently flagged as exploited, all worth clearing in the same maintenance window.
| CVE | Type | CWE | CVSS |
|---|---|---|---|
| CVE-2026-55007 | Remote code execution | CWE-415 (double free) | 8.1 High |
| CVE-2026-69355 | Remote code execution | CWE-73 (external control of file name/path) | 8.8 High |
| CVE-2026-69356 | Spoofing | CWE-79 (cross-site scripting) | 9.3 Critical |
| CVE-2026-69641 | Elevation of privilege | CWE-862 (missing authorization) | 9.1 Critical |
| CVE-2026-69380 | Elevation of privilege | CWE-862 (missing authorization) | 8.1 High |
Exchange keeps landing on CISA's KEV list
Query our own graph for Microsoft Exchange Server CVEs that CISA has ever added to KEV, and the pattern is stark: 20 entries stretching back to 2017, ten of them from the ProxyLogon/ProxyShell year alone. CVE-2026-55007 is not on that list — not yet, and maybe never. But Exchange's history is exactly why ZDI treats "not yet exploited" as a narrow window, not a reason to wait.
| Label | Value |
|---|---|
| 2017 | 1 |
| 2018 | 1 |
| 2020 | 2 |
| 2021 | 10 |
| 2022 | 3 |
| 2023 | 1 |
| 2024 | 1 |
| 2026 | 1 |
What to do now
- Identify every on-prem Exchange Server 2019 CU14, CU15, and Subscription Edition RTM build in your environment — Exchange Online is not affected.
- Update CU14 builds to 15.02.1544.046 or later, CU15 builds to 15.02.1748.051 or later, and Subscription Edition RTM to 15.02.2562.049 or later.
- Apply the fix even if content indexing feels like a low-priority service — it runs by default on every mailbox server.
- Clear the other four Exchange fixes from the same release (CVE-2026-69355, -69356, -69641, -69380) in the same maintenance window; none has a published workaround either.
- Don't deprioritize this because it's not in KEV yet — 20 previous Exchange CVEs eventually got there, several years after disclosure.
CVE and KEV data as of September 20, 2026