CVE-2026-62914 – Microsoft Exchange Server 2016 CU23

CVSS 7.3 IMPORTANT High with EoP or RCE – Expedited Deployment

“Multiple Exchange flaws create paths to code execution, privilege escalation, and broader server compromise.”

Microsoft Exchange Server 2016 CU23 is affected by six vulnerabilities spanning remote code execution, privilege escalation, and other security weaknesses. CVE-2026-62913 has a CVSS score of 8.8, High severity. CVE-2026-62911 has a CVSS score of 8.0, High severity. CVE-2026-62910 has a CVSS score of 7.2, High severity. CVE-2026-62912 has a CVSS score of 6.5, Medium severity. CVE-2026-62914 has a CVSS score of 7.3, High severity. CVE-2026-62915 has a CVSS score of 6.5, Medium severity.

The patch addresses the affected Exchange Server components and reduces the risk of server compromise, unauthorized privilege gains, and disruption.

Key Details

Affected Product
Microsoft Exchange Server
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
CWE Classification
CWE-79
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.