Junglewise Threat Intelligence

CVE-2026-62912: Microsoft Exchange Server deserialization vulnerability

CVE-2026-62912 · Severity: medium · CVSS 6.5 · Published 2026-08-11

Technologies: Microsoft Exchange Server. Vendors: Microsoft.

Executive brief

Microsoft Exchange Server, a widely-used email and collaboration platform, contains a flaw in how it processes untrusted data. An authorized user could exploit this to crash the service, causing email and collaboration disruptions. While the vulnerability requires valid user credentials to trigger, it poses a risk to business continuity when activated by compromised accounts or malicious insiders.

Technical details

The vulnerability is a deserialization flaw in Microsoft Exchange Server that processes untrusted data without proper validation. An authenticated attacker with network access can send a specially crafted request that triggers unsafe deserialization, leading to a denial-of-service condition. The attack requires valid Exchange credentials but no special privileges; once triggered, it can crash Exchange services or cause resource exhaustion. Microsoft has released security updates to address the unsafe deserialization logic.

Affected products

  • Microsoft Exchange Server

Timeline

  • 2026-08-11: disclosed

References

Related threats