Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server - CVE-2026-69382
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose credentials.
The vulnerability exists due to use of a broken or risky cryptographic algorithm in Microsoft Exchange Server when processing repeated requests using a valid encrypted authentication cookie. A remote attacker can make repeated requests to infer protected credentials to disclose credentials.