Original 0-day vulnerabilities discovered by Aretiq AI. We follow responsible disclosure — advisories are published only after vendors have had the opportunity to release patches. Read our Disclosure Policy.
CVE-2026-62912 — Microsoft Exchange Server Deserialization Denial of Service
Summary A deserialization of untrusted data vulnerability in Microsoft Exchange Server allows any user with a mailbox account to crash the server repeatedly, causing sustained denial of service across the entire organization. The only prerequisite is a valid email account on the target Exchange server — no administrative privileges or special roles are required. The vulnerability was reported as a denial of service; however, the underlying deserialization primitive may carry remote code execution potential given the right gadget chain. No RCE gadget was identified during our research. ...