CVE-2026-62915: Microsoft Exchange Server Security Feature Bypass Vulnerability
Microsoft Exchange Server Security Feature Bypass Vulnerability
Other sources
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62915?
The severity of CVE-2026-62915 is classified as medium with a score of 6.5.
How do I fix CVE-2026-62915?
To fix CVE-2026-62915, apply the available patch from Microsoft for the affected Exchange Server versions.
What systems are affected by CVE-2026-62915?
CVE-2026-62915 affects Microsoft Exchange Server 2019, Microsoft Exchange Server Subscription Edition RTM, Microsoft Exchange Server 2016, and Microsoft Exchange Server Subscription Edition.
What type of vulnerability is CVE-2026-62915?
CVE-2026-62915 is a security feature bypass vulnerability in Microsoft Exchange Server.
Can CVE-2026-62915 be exploited remotely?
Yes, CVE-2026-62915 can be exploited remotely as it allows an authorized attacker to bypass security features over a network.