CVE-2026-62912 — Microsoft Exchange Server Deserialization Denial of Service

Summary A deserialization of untrusted data vulnerability in Microsoft Exchange Server allows any user with a mailbox account to crash the server repeatedly, causing sustained denial of service across the entire organization. The only prerequisite is a valid email account on the target Exchange server — no administrative privileges or special roles are required. The vulnerability was reported as a denial of service; however, the underlying deserialization primitive may carry remote code execution potential given the right gadget chain. No RCE gadget was identified during our research. ...

August 11, 2026 · 2 min · Aretiq AI