
Breakdown of Exchange Server vulnerabilities by version from the August 2026 Patch Tuesday: 🖥️ Exchange Server 2016, 2019, Subscription Edition (All supported on‑premises versions are affected by each CVE below) 🔵 CVE-2026-62910 – Elevation of Privilege (resource injection) 🔵 CVE-2026-62911 – Elevation of Privilege (auth bypass replay attack, CVSS 8.0) 🔵 CVE-2026-62912 – Denial of Service (deserialization flaw) 🔵 CVE-2026-62913 – Remote Code Execution (heap buffer overflow, CVSS 8.8) 🔵 CVE-2026-62914 – Spoofing (XSS) 🔵 CVE-2026-62915 – Security Feature Bypass (missing authorization checks) Exchange Online is already protected, but on‑premises Exchange 2016, 2019, and Subscription Edition must be patched immediately. 🔵 CVE-2026-62914 – Spoofing (XSS) 🔵 CVE-2026-62915 – Security Feature Bypass (missing authorization checks)
Post summary
This advisory lists multiple Exchange Server CVEs with technical details and urges on‑premises users to apply patches immediately.

