CVE-2026-62915 – Microsoft Exchange Server 2016 CU23
CVSS 6.5
MODERATE
High with EoP or RCE – Expedited Deployment
“Multiple Exchange flaws create paths to code execution, privilege escalation, and broader server compromise.”
Microsoft Exchange Server 2016 CU23 is affected by six vulnerabilities spanning remote code execution, privilege escalation, and other security weaknesses. CVE-2026-62913 has a CVSS score of 8.8, High severity. CVE-2026-62911 has a CVSS score of 8.0, High severity. CVE-2026-62910 has a CVSS score of 7.2, High severity. CVE-2026-62912 has a CVSS score of 6.5, Medium severity. CVE-2026-62914 has a CVSS score of 7.3, High severity. CVE-2026-62915 has a CVSS score of 6.5, Medium severity.
The patch addresses the affected Exchange Server components and reduces the risk of server compromise, unauthorized privilege gains, and disruption.
Key Details
- Affected Product
- Microsoft Exchange Server
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-862
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.