Microsoft has released security updates for six vulnerabilities affecting Exchange Server. The issues include remote code execution (RCE), privilege escalation, denial-of-service (DoS), spoofing, and security feature bypass vulnerabilities.
The vulnerabilities were disclosed on August 11, 2026, with an update for CVE-2026-62913 published the following day.
Microsoft Exchange Server Security Flaws
The most serious issue is CVE-2026-62913, a remote code execution vulnerability with a CVSS score of 8.8. It is caused by a heap-based buffer overflow.
An attacker with low-level privileges could exploit the flaw remotely without requiring any action from the victim. Successful exploitation could allow the attacker to execute malicious code on an affected Exchange Server.
Another important vulnerability is CVE-2026-62911, an elevation-of-privilege flaw rated Critical by Microsoft, with a CVSS score of 8.0.
The vulnerability is related to an authentication bypass technique. An attacker with low privileges could potentially use it to gain additional permissions, although exploitation requires user interaction.
Because Exchange Server handles corporate email, communications, attachments, and other sensitive information, vulnerabilities in the platform can present a significant risk to organizations.
Affected Vulnerabilities
- CVE-2026-62910 – Elevation of Privilege. An Important-rated resource injection flaw with a CVSS score of 7.2. Exploitation requires high privileges.
- CVE-2026-62911 – Elevation of Privilege. A Critical authentication bypass vulnerability with a CVSS score of 8.0. Low privileges and user interaction are required.
- CVE-2026-62912 – Denial of Service. An Important deserialization vulnerability with a CVSS score of 6.5 that could disrupt Exchange services.
- CVE-2026-62913 – Remote Code Execution. A heap-based buffer overflow with a CVSS score of 8.8 that could allow remote code execution.
- CVE-2026-62914 – Spoofing. An Important cross-site scripting vulnerability with a CVSS score of 7.3.
- CVE-2026-62915 – Security Feature Bypass. An Important authorization flaw with a CVSS score of 6.5 that could allow an attacker to bypass certain access controls.
What Organizations Should Do
Exchange administrators should prioritize these updates, particularly for internet-facing servers.
After applying the patches, teams should verify that updates were successfully installed across all Exchange roles and continue monitoring for unusual authentication, administrative activity, and unexpected server behavior.
Keeping Exchange Server fully patched is especially important because it sits at the center of many organizations’ email and communication infrastructure.