Resource Injection Vulnerability in Microsoft Exchange Server by Microsoft
CVE-2026-62910
7.2HIGH
Key Information:
What is CVE-2026-62910?
Microsoft Exchange Server contains a vulnerability due to improper control of resource identifiers, allowing authorized attackers to leverage this flaw for privilege escalation. By exploiting this vulnerability, attackers can gain unauthorized access and manipulate system resources over a network. Organizations using affected versions of Microsoft Exchange Server should implement the recommended security patches to mitigate this risk.
Affected Version(s)
Microsoft Exchange Server 2016 Cumulative Update 23 x64-based Systems 15.01.0.0 < 15.01.2507.072
Microsoft Exchange Server 2019 Cumulative Update 14 x64-based Systems 15.02.0.0 < 15.02.1544.044
Microsoft Exchange Server 2019 Cumulative Update 15 x64-based Systems 15.02.0.0 < 15.02.1748.049