
An authenticated attacker can crash Microsoft Exchange Server via a deserialization flaw — taking down email for entire organizations. CVE-2026-62912 · CVSS 6.5 · All supported Exchange versions affected (2016 CU23, 2019 CU14/CU15, SE RTM). Discovered by Aretiq AI, responsibly disclosed to Microsoft, and patched today in the August 2026 Patch Tuesday updates. https://aretiq.ai/discoveries/cve-2026-62912-microsoft-exchange-server-deserialization-dos/
Post summary
The post announces the discovery of a deserialization flaw in Microsoft Exchange Server, provides technical details and affected versions, and reports that Microsoft has released a patch in the August 2026 Patch Tuesday updates.


