CVE-2026-55007: 34 Swiss Exchange Servers Need the Fix
CVE-2026-55007 affected 34 of 70 Swiss Exchange servers checked. Another 11 public servers still run Exchange 2010, unsupported since October 2020.
34 of the 70 Swiss Exchange servers we checked were running versions affected by CVE-2026-55007. Separately, 11 still run Exchange 2010, which Microsoft stopped supporting in October 2020.
CVE-2026-55007 can let an attacker take control of an affected Exchange server by emailing it a malicious Visio attachment. The attacker does not need an account, and nobody needs to open the file. Microsoft rates it 8.1 out of 10 because the server must also remain low on memory.
We checked the Swiss exposure on 09 September, 1 day after disclosure. 5 servers already had the security update and 34 still needed it.
What CVE-2026-55007 does
The flaw can make Exchange release the same piece of memory twice. That can crash the server or let an attacker run code on it.
The route into this flaw is email. An attacker sends a crafted Visio attachment to an affected Exchange server. Exchange can inspect the attachment automatically, so nobody needs to open it. Microsoft says the attacker does not need an Exchange account.
The server must remain low on memory before the attack can work. That makes the attack less reliable, but the attacker can still reach the vulnerable feature without an account.
As of 09 September, Microsoft reported no observed exploitation and assessed exploitation as less likely. The flaw was also absent from the current United States known exploited vulnerabilities catalog. No public probability score was available yet. These status signals can change and do not justify leaving an internet accessible mail server behind.
The affected Exchange versions
Microsoft lists 3 affected Exchange versions. Exchange Server 2016 is outside that list, so we keep those servers separate.
| Exchange version | Updated version | Security update |
|---|---|---|
| Exchange Server 2019 CU14 | 15.2.1544.46 | KB5121610 |
| Exchange Server 2019 CU15 | 15.2.1748.51 | KB5121609 |
| Exchange Server Subscription Edition RTM | 15.2.2562.49 | KB5121608 |
All 3 updates require a restart. Microsoft does not list a temporary fix. Identify the installed Exchange version, install its matching update, restart Exchange, and confirm the new version locally.
What we found in Switzerland
The public exposure index returned 75 records. Removing repeated entries left 72 Exchange servers. We removed 2 servers outside Switzerland, leaving 70 Swiss servers to check.
We made a normal request to each server’s public Exchange sign in page and read the version number it returned. We did not log in, send a file, follow another address, or use the vulnerable attachment feature.
Inside the Swiss set, 66 of 70 servers answered and 63 revealed their Exchange version. We repeated the public version check on the 23 servers that were initially unresolved and identified 16 more. The final results are:
| Result | Swiss servers | Meaning |
|---|---|---|
| Needs the security update | 34 | The server runs a version affected by this flaw |
| Already updated | 5 | The server reports the new security update |
| Could not be classified | 7 | The server did not reveal its exact version |
| Server on an older version | 24 | Microsoft does not say whether that version is affected |
All 34 affected results were confirmed by a second public version check. The 7 unknown servers are excluded from both the affected and updated totals.
The largest affected sector was telecom and hosting with 9 servers. Education followed with 7. Healthcare had 4, the public sector had 4, and banking and insurance had 2. These labels describe the network owner or operating organization. They do not identify a customer or prove who owns the Exchange application.
11 servers still run Exchange 2010
The 24 servers on older Exchange versions produced the sharpest secondary finding. 11 run Exchange 2010, which reached the end of support in October 2020. Another 11 run Exchange 2016, which reached the end of support in October 2025. The remaining 2 run Exchange 2019 CU12 and CU13.
Microsoft did not include these older versions in its CVE notice, so we do not count the 24 servers as affected by this specific flaw. Their age and support status remain separate security concerns.
The August version dominates
The sharpest pattern among the affected servers is recency. 22 of the 34 ran Subscription Edition version 15.2.2562.46, released on 11 August. It remained Microsoft’s newest Subscription Edition release until version 15.2.2562.49 arrived on 08 September.
This is the normal patch interval becoming visible on the day after a security release. The 5 updated servers show that some operators had already moved within that window.
The oldest affected version in the Swiss set was released on 10 February 2025, which is 576 days before our check. That date does not reveal every update ever installed on the server.
This pattern also appeared in our earlier Swiss SharePoint measurement. A release date can turn a version string into an operational signal. It shows whether a team missed the latest fix, several monthly releases, or an entire support cycle.
How to check your own Exchange servers
Start with your own server list. Record the installed Exchange version on every server and compare it with the updated versions above, including servers that are not reachable from the internet.
Then run Microsoft’s Exchange Health Checker and review its security update result. Install the matching September update, restart the server, and run the check again. Check every Exchange server, including servers that share one public address.
If the server does not reveal a version, this check gives no answer. If Microsoft does not assess the version, we keep it separate from both the affected and updated totals.
Sentinel scans the visitor’s public IP and emails an AI written report. The public Exchange version check described above remains a manual step.
Patch first, then verify
Install KB5121610 for Exchange 2019 CU14, KB5121609 for Exchange 2019 CU15, or KB5121608 for Exchange Subscription Edition RTM. Restart the server and confirm the installed version locally.
The first Swiss measurement already shows both sides: 5 servers have the security update, while 34 run affected versions. The next useful number is how quickly that second group shrinks.