CVE-2026-62912: Microsoft Exchange Server Denial of Service Vulnerability
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
Other sources
Microsoft Exchange Server Denial of Service Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1748.049Patch KB5121574 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1544.044Patch KB5121575 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.2562.046Patch KB5121573 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2507.072Patch KB5121576
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62912?
CVE-2026-62912 has a medium severity rating of 6.5.
How do I fix CVE-2026-62912?
To mitigate CVE-2026-62912, ensure that you apply the latest security updates provided by Microsoft for Exchange Server.
What impact does CVE-2026-62912 have on Microsoft Exchange Server?
CVE-2026-62912 allows an authorized attacker to execute a denial of service attack against Microsoft Exchange Server.
Which versions of Microsoft Exchange Server are affected by CVE-2026-62912?
CVE-2026-62912 affects Microsoft Exchange Server 2019, 2016, and the Subscription Edition RTM.
What is the nature of the vulnerability in CVE-2026-62912?
CVE-2026-62912 involves deserialization of untrusted data, leading to potential denial of service.