Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Unauthenticated Command Injection on Internet‑Facing Mail Servers (CVE‑2026‑73570) Enables Remote Code Execution

A new CVE‑2026‑73570 vulnerability lets attackers inject OS commands into Microsoft Exchange mail servers without authentication. The flaw threatens data confidentiality and service continuity, highlighting the importance of robust vulnerability‑management controls for audit readiness.

LiveThreat™ Intelligence · 📅 September 30, 2026· 📰 microsoft.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
2 recommended
📰
Source
microsoft.com

Unauthenticated Command Injection on Internet‑Facing Mail Servers (CVE‑2026‑73570)

What It Is – A newly disclosed vulnerability (CVE‑2026‑73570) allows an unauthenticated attacker to inject arbitrary operating‑system commands into the processing pipeline of internet‑facing mail servers. The flaw resides in the mail‑transfer component’s handling of specially crafted SMTP headers.

Exploitability – Public proof‑of‑concept code has been released, and the vulnerability is exploitable without any credentials. Microsoft’s advisory assigns a CVSS v3.1 base score of 8.6 (High).

Affected Products – The issue impacts Microsoft Exchange Server versions 2016, 2019, and the cloud‑based Exchange Online service that expose SMTP endpoints to the public internet.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous vulnerability‑management controls that capture evidence of patch status and configuration hygiene.
  • A successful injection can lead to data exfiltration, service disruption, or lateral movement, eroding the audit trail that regulators expect.
  • Enterprises that can show timely remediation and documented remediation workflows satisfy a core control objective that maps across NIST CSF 2.0, ISO 27001, and other frameworks.

Recommended Actions

  • Map the finding to the “Vulnerability Management” control objective in your governance framework and record the current remediation status.
  • Deploy the Microsoft‑provided out‑of‑band patch or mitigation guidance immediately on all exposed Exchange servers.
  • Verify remediation through automated scanning and retain the scan reports as audit evidence.
  • Review inbound SMTP filtering rules to ensure they block malformed headers that could trigger the injection path.

Source: Microsoft Security Blog – CVE‑2026‑73570

📰 Original Source
https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →