CVE-2026-62910: Microsoft Exchange Server Elevation of Privilege Vulnerability
Published Aug 11, 2026
·Updated
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Other sources
Microsoft Exchange Server Elevation of Privilege Vulnerability
— Microsoft
Affected Software
42 affected componentsFixes available
Microsoft Exchange Server 2019=14
15.02.1544.044
Microsoft Exchange Server 2016=23
15.01.2507.072
Microsoft Exchange Server 2019=15
15.02.1748.049
Microsoft Exchange Server Subscription Edition RTM<15.02.2562.046
15.02.2562.046
Microsoft Exchange Server=2016
Microsoft Exchange Server=2016-cumulative_update_1
Microsoft Exchange Server=2016-cumulative_update_10
Microsoft Exchange Server=2016-cumulative_update_11
Microsoft Exchange Server=2016-cumulative_update_12
Microsoft Exchange Server=2016-cumulative_update_13
Microsoft Exchange Server=2016-cumulative_update_14
Microsoft Exchange Server=2016-cumulative_update_15
Microsoft Exchange Server=2016-cumulative_update_16
Microsoft Exchange Server=2016-cumulative_update_17
Microsoft Exchange Server=2016-cumulative_update_18
Microsoft Exchange Server=2016-cumulative_update_19
Microsoft Exchange Server=2016-cumulative_update_2
Microsoft Exchange Server=2016-cumulative_update_20
Microsoft Exchange Server=2016-cumulative_update_21
Microsoft Exchange Server=2016-cumulative_update_22
Microsoft Exchange Server=2016-cumulative_update_3
Microsoft Exchange Server=2016-cumulative_update_4
Microsoft Exchange Server=2016-cumulative_update_5
Microsoft Exchange Server=2016-cumulative_update_6
Microsoft Exchange Server=2016-cumulative_update_7
Microsoft Exchange Server=2016-cumulative_update_8
Microsoft Exchange Server=2016-cumulative_update_9
Microsoft Exchange Server=2019
Microsoft Exchange Server=2019-cumulative_update_1
Microsoft Exchange Server=2019-cumulative_update_10
Microsoft Exchange Server=2019-cumulative_update_11
Microsoft Exchange Server=2019-cumulative_update_12
Microsoft Exchange Server=2019-cumulative_update_13
Microsoft Exchange Server=2019-cumulative_update_2
Microsoft Exchange Server=2019-cumulative_update_3
Microsoft Exchange Server=2019-cumulative_update_4
Microsoft Exchange Server=2019-cumulative_update_5
Microsoft Exchange Server=2019-cumulative_update_6
Microsoft Exchange Server=2019-cumulative_update_7
Microsoft Exchange Server=2019-cumulative_update_8
Microsoft Exchange Server=2019-cumulative_update_9
Microsoft Exchange Server Subscription Edition<15.02.2562.046
Remediation
Event History
Aug 11, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:04 PM
Data Sourced
via MITRE·05:04 PM
DescriptionSeverity
Data Sourced
via NVD·05:18 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-62910?
CVE-2026-62910 has a severity rating of 8.8, classified as high.
2
What vulnerability does CVE-2026-62910 represent?
CVE-2026-62910 represents an elevation of privilege vulnerability in Microsoft Exchange Server.
3
How do I fix CVE-2026-62910?
To fix CVE-2026-62910, apply the available patch from Microsoft for your version of Exchange Server.
4
Who is affected by CVE-2026-62910?
CVE-2026-62910 affects users of Microsoft Exchange Server, including versions 2019, 2016, and Subscription Edition.
5
What can an attacker achieve with CVE-2026-62910?
An attacker can elevate privileges over a network if they exploit CVE-2026-62910.