Description
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
Published: 2026-08-11
Score: 6.5 Medium
EPSS: 1.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is caused by the deserialization of untrusted data, allowing an attacker with authorized access to send crafted payloads that trigger a crash of the Exchange service, resulting in a denial of service. The weakness is categorized as CWE‑502, which involves handling of untrusted data leading to security failures. Because the crash terminates the service, the attack can interrupt communication, potentially affecting email availability for users.

Affected Systems

This issue affects Microsoft Exchange Server 2016 when it is running Cumulative Update 23, Exchange Server 2019 when it is running Cumulative Update 14 or 15, and the Exchange Server Subscription Edition at RTM. All affected versions require the server to be within the respective update levels for mitigation.

Risk and Exploitability

With a CVSS score of 6.5 the vulnerability is considered moderate to high severity. The EPSS score of 1% indicates a very low but nonzero probability of exploitation, and it is not listed in the CISA KEV catalog, suggesting that no documented public exploits are known. The attack requires an authorized user and is carried out over the network, so the risk is limited to trusted connections. Nevertheless, the potential to interrupt service for an entire organization makes it a priority to remediate.

Generated by OpenCVE AI on August 13, 2026 at 01:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Exchange Server Cumulative Update that addresses CVE‑2026‑62912 (Cumulative Update 23 for 2016, Cumulative Update 14 or 15 for 2019, and any subsequent patch for the Subscription Edition).
  • If a patch cannot be applied immediately, restrict inbound connections to the Exchange server to only trusted administrators and block requests that target the deserialization processing paths.
  • Continuously monitor the Exchange logs for abnormal deserialization activity and review configuration to ensure only trusted accounts have write access to the affected components.

Generated by OpenCVE AI on August 13, 2026 at 01:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft exchange Server
Microsoft exchange Server Subscription Edition
CPEs cpe:2.3:a:microsoft:exchange_server:2016:-:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_10:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_11:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_12:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_13:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_14:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_15:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_16:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_17:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_18:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_19:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_1:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_20:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_21:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_22:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_2:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_3:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_4:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_5:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_6:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_7:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_8:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_9:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2019:-:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_10:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_11:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_12:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_13:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_1:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_2:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_3:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_4:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_5:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_6:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_7:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_8:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_9:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_subscription_edition:*:*:*:*:*:*:*:*
Vendors & Products Microsoft exchange Server
Microsoft exchange Server Subscription Edition

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Exchange Server 2019 Cumulative Update 15
Vendors & Products Microsoft microsoft Exchange Server 2019 Cumulative Update 15

Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
Title Microsoft Exchange Server Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft exchange Server 2016
Microsoft exchange Server 2019
Microsoft exchange Server Se
Weaknesses CWE-502
CPEs cpe:2.3:a:microsoft:exchange_server_2016:*:cumulative_update_23:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_14:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_15:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_se:*:RTM:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft exchange Server 2016
Microsoft exchange Server 2019
Microsoft exchange Server Se
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Exchange Server Exchange Server 2016 Exchange Server 2019 Exchange Server Se Exchange Server Subscription Edition Microsoft Exchange Server 2019 Cumulative Update 15
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:05:28.911Z

Reserved: 2026-07-14T21:25:21.036Z

Link: CVE-2026-62912

cve-icon Vulnrichment

Updated: 2026-08-12T13:26:44.228Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:45.197

Modified: 2026-08-13T18:57:36.450

Link: CVE-2026-62912

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T01:30:05Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data