// Microsoft 365HIGH
Microsoft patched six Exchange Server vulnerabilities affecting Exchange Server Subscription Edition, 2019, and 2016 via August 2026 Patch Tuesday. CVE-2026-62913 is a critical remote code execution flaw (CVSS 8.8) exploitable over the network without user interaction via heap-based buffer overflow. CVE-2026-62911 (CVSS 8.0) enables authentication bypass and privilege escalation, demonstrated at Pwn2Own Berlin. Additional flaws include DoS, privilege escalation, spoofing, and authorization bypass impacts.
- Microsoft Exchange Server Vulnerabilities Enables DoS, Privilege(opens in a new tab)
- Microsoft Exchange Server Vulnerabilities Enables DoS, Privilege(opens in a new tab)
// Get alerts for Microsoft 365