CVE-2026-62912

Summary

Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.

Affected Software

VendorProductVersion RangeStatus
MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 2315.01.0.0 < 15.01.2507.072affected
MicrosoftMicrosoft Exchange Server 2019 Cumulative Update 1415.02.0.0 < 15.02.1544.044affected
MicrosoftMicrosoft Exchange Server 2019 Cumulative Update 1515.02.0.0 < 15.02.1748.049affected
MicrosoftMicrosoft Exchange Server Subscription Edition RTM15.02.0.0 < 15.02.2562.046affected

Weaknesses

  • CWE-502: CWE-502: Deserialization of Untrusted Data

References