Securing Your Law Firm logoSecuring Your Law Firm
Back to resources
Vulnerability Alert2026-09-09By Securing Your Law Firm

Your Law Firm’s Email Server Can Be Attacked Before Anyone Opens the Message

A new Exchange Server flaw shows why law-firm email infrastructure can be exposed before anyone clicks – and what your firm should verify now.

Your Law Firm’s Email Server Can Be Attacked Before Anyone Opens the Message

By Securing Your Law Firm

Start the free Zero-Access Exposure Review™ | See the Law Firm Security Baseline

Most email-security advice starts with one warning: do not click suspicious links or open unexpected attachments.

But some attacks begin before anyone opens the message.

On September 8, 2026, Microsoft released updates for CVE-2026-55007, a remote-code-execution vulnerability in Microsoft Exchange Server. According to the Zero Day Initiative, an unauthenticated attacker could send an email with a malicious Visio attachment and target an affected server while it processes the message.

The practical question for a firm manager is not only “Will someone click?” It is “What is receiving and processing our email?”

Why This Matters to Your Firm

Email receives messages from unknown internet users every day. It may also contain or provide access to:

  • Confidential client communications
  • Matter documents and attachments
  • Court notices and filing information
  • Payment instructions
  • Password-reset messages

Many firms use Microsoft 365 and reasonably assume Microsoft operates the entire email environment. That may be true. However, some firms still have an on-premises Exchange Server for hybrid functions, mail routing, administration, or a legacy configuration.

The firm may not know that server still exists. If it accepts internet email, it remains part of the firm’s external attack surface. Our article on external attack surface management for law firms explains why that inventory matters.

Visible, Vulnerable, and Compromised Are Different

These terms should not be treated as interchangeable:

  • Visible: Outside information indicates that email infrastructure exists or appears reachable.
  • Vulnerable: Internal verification confirms an affected Exchange version is installed and the update is missing.
  • Compromised: Logs, forensic evidence, or other findings show unauthorized activity.

A public review may identify routing or an exposed service. It cannot prove the exact Exchange build, patch status, or compromise. Microsoft also indicated that successful exploitation would be difficult and did not report active exploitation with the update. There is no reason to panic, but there is a reason to verify.

Five Questions for Your IT Provider

Ask your MSP or Microsoft 365 administrator:

  1. Do we operate any on-premises Microsoft Exchange Server?
  2. Is an Exchange server still present for a hybrid Microsoft 365 configuration?
  3. What version and build is installed?
  4. Was the September 8, 2026 security update applied?
  5. What evidence confirms each answer?

If the firm uses Exchange Online only and has no on-premises Exchange Server, this specific server vulnerability may not apply. Your provider should be able to establish that clearly.

How Our Services Help

You should not have to become an Exchange administrator to ask these questions.

Free Zero-Access Exposure Review™

Our Zero-Access Exposure Review™ examines publicly available information without logging into your systems. It can identify visible email infrastructure and signals that deserve follow-up.

It cannot confirm an internal Exchange version or patch. Instead, it gives you a practical starting point for a focused conversation with your MSP.

Law Firm Security Baseline

Our $1,995 Law Firm Security Baseline goes further. It reviews evidence for important controls, identifies gaps, and gives leadership a documented view of what is working, what needs attention, and what has not been verified.

The Baseline is useful when your firm needs more than an outside signal. It helps turn questions about email, Microsoft 365 identity, patching, and logging into evidence your leadership, clients, or insurer can understand.

Email Security Hardening

If the issue is broader email risk, our Email Security service helps strengthen SPF, DKIM, DMARC, sender inventory, and impersonation controls. Those controls do not replace Exchange patching, but they address other ways attackers can use or imitate a firm’s email domain.

These services complement an existing MSP or IT provider. They do not replace the team responsible for operating and patching your systems.

Know What Is Receiving Your Firm’s Email

CVE-2026-55007 is a reminder that an internet-facing asset does not need an obvious login screen. Sometimes the exposed door is simply the server accepting the next message.

Start with a Zero-Access Exposure Review™ to understand what can be observed from outside your firm and what your IT provider should verify next.

Related Reading

Sources