Denial of Service Vulnerability in Microsoft Exchange Server by Microsoft
CVE-2026-62912

6.5MEDIUM

What is CVE-2026-62912?

A vulnerability exists in Microsoft Exchange Server due to improper handling of untrusted data during deserialization. This flaw enables an authorized attacker to perform denial of service attacks over the network, potentially disrupting service availability for legitimate users. Organizations using affected versions of Microsoft Exchange Server should apply the necessary patches and follow security best practices to mitigate risks associated with this vulnerability.

Affected Version(s)

Microsoft Exchange Server 2016 Cumulative Update 23 x64-based Systems 15.01.0.0 < 15.01.2507.072

Microsoft Exchange Server 2019 Cumulative Update 14 x64-based Systems 15.02.0.0 < 15.02.1544.044

Microsoft Exchange Server 2019 Cumulative Update 15 x64-based Systems 15.02.0.0 < 15.02.1748.049

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.