CVE-2026-62910
Microsoft Exchange Server Elevation of Privilege Vulnerability
Description
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
In plain language
AI Act nowCVE-2026-62910 is a Microsoft Exchange Server security bug where an authenticated (logged-in) user could use a special network resource reference to gain higher administrative rights; most small businesses should update if they run an affected Exchange version.
CVE-2026-62910 is an authorized network elevation of privilege in Microsoft Exchange Server caused by improper handling of resource identifiers (resource injection), enabling a valid authenticated account to gain higher privileges over the server.
What to do now
- Check your Microsoft Exchange Server version (and whether you’re using Exchange Server 2016 CU 23, Exchange Server 2019 CUs 14/15, or Exchange Server Subscription Edition RTM).
- If you are on an affected version, upgrade to the fixed versions: 15.01.2507.072 (Exchange Server 2016 CU 23), 15.02.1544.044 (Exchange Server 2019 CU 14), 15.02.1748.049 (Exchange Server 2019 CU 15), or 15.02.2562.046 (Exchange Server Subscription Edition).
- If you can’t upgrade right away, immediately review Exchange access: confirm all user accounts and service accounts are legitimate, disable any unused accounts, and tighten authentication/account access controls while you plan the update.
- After patching, verify Exchange services start normally and monitor for unusual admin-level activity around authentication and privilege changes.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:HPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
References
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62910 and every CVE in our database. Create a free account — no credit card required.
Create Free Account