CVE-2026-62911

Published Aug 11, 2026

Last updated 11 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-62911 is an authentication bypass vulnerability affecting Microsoft Exchange Server, specifically versions 2016, 2019, and Subscription Edition. This flaw, categorized as a capture-replay authentication bypass, allows an authorized attacker to elevate privileges over a network. It was publicly demonstrated as part of a successful Microsoft Exchange attack at Pwn2Own Berlin 2026. The vulnerability enables an attacker to intercept authentication material and then replay it to gain higher-privileged access to Exchange resources. This can lead to an attacker taking over user mailboxes, allowing them to read or send emails and download attachments.

Description
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Source
secure@microsoft.com
NVD status
Modified
Products
exchange_server, exchange_server_subscription_edition

Risk scores

CVSS 3.1

Type
Secondary
Base score
8
Impact score
5.9
Exploitability score
2.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-294

Social media

Hype score
Not currently trending
  1. 🚨 Critical Exchange Authentication Bypass (#CVE-2026-62911) Threatens 22,000 Servers: A GRC & Patching Emergency + Video -Prediction: 📈 2 Positive | 📉 3 Negative https://t.co/Xsa86mQqcz Educational Purposes!

    @UndercodeUpdate

    6 Sept 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Cisco ya parchó la CVE-2026-20212 en Nexus 9000 y ahí tenés el contraste con lo que Chema viene marcando: cuando una debilidad queda expuesta, el tiempo juega para el atacante. En Exchange pasó algo parecido con CVE-2026-62911. Una PoC pública y 21.899 servidores todavía

    @FedeJoelH

    5 Sept 2026

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 22,000 Microsoft Exchange servers are STILL exposed to CVE-2026-62911 — a critical auth bypass flaw (CVSS 8.0). Exploit code is already public. Patch guide + detection commands here 👇 https://t.co/QMNMmywsTr #CyberSecurity #CVE https://t.co/PU3PQoVM1m

    @Xpert4Cyber

    5 Sept 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 【Vulnerability Disclosure | CVE Spotlight】 😱Exchange Server Authentication Flaw Chain Can Lead to SYSTEM-Level Access (CVE-2026-62911) A high-severity authentication bypass and privilege escalation vulnerability, CVE-2026-62911 (CVSS 8.0), has been disclosed in Microsoft

    @hackprove_

    4 Sept 2026

    113 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)(約2万2,000台のMicrosoft Exchangeサーバーが重大な脆弱性CVE-2026-62911に未対応) #HelpNetSecurity (Sep 2) https://t.co/Jl2G2gFPD0

    @foxbook

    3 Sept 2026

    230 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) - https://t.co/FdZZBkoKZb - @Shadowserver- #MicrosoftExchange #CVE #vulnerability #exploit #Cybersecurity #CyberSecurityNews #SecurityNews

    @helpnetsecurity

    2 Sept 2026

    658 Impressions

    2 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  7. Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911): Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans… https://t.co/BG2y0yipQ

    @shah_sheikh

    2 Sept 2026

    66 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🔴 CVE-2026-62911 — Microsoft Exchange at risk Public PoC is now available while 21,899 Internet-facing Exchange servers remain vulnerable. No confirmed mass exploitation yet — https://t.co/Z17ChEWLTC #CVE #CVE202662911 #MicrosoftExchange #Exchange #PoC #CyberSecurity #I

    @stem__shop

    2 Sept 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Exchange Serverの事前認証RCEの概念実証(PoC)であるCVE-2026-62911が公開されました CVE-2026-62911 Exchange Server Pre-Auth RCE PoC Released #DailyCyberSecurity (Sep 1) https://t.co/qWM2gUPgjj

    @foxbook

    2 Sept 2026

    262 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  10. ⚠️ URGENT: 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911! 🛡️ This critical authentication-bypass vulnerability (CVSS 8.0) allows attackers to seize control of enterprise email infrastructure. Shadowserver Foundation reports 21,899 unique IPs

    @mazin_dr38737

    1 Sept 2026

    73 Impressions

    3 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 🚨 [MASS EXPOSURE] — NEARLY 22,000 MICROSOFT EXCHANGE SERVERS ARE STILL INTERNET-EXPOSED AND VULNERABLE TO A MAILBOX-HIJACK FLAW Shadowserver counted **21,899 exposed Exchange servers** still vulnerable to CVE-2026-62911 — including roughly 6,200 in the U.S. and 5,100 in G

    @XQOPTRX

    1 Sept 2026

    98 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. ⚠️ 21,000+ Microsoft Exchange Servers Remain Exposed to Active CVE-2026-62911 Exploitation Details: https://t.co/MA2JPNX1Ym Nearly 22,000 Microsoft Exchange servers worldwide are still running unpatched for CVE-2026-62911, a critical authentication-bypass vulnerability that

    @The_Cyber_News

    1 Sept 2026

    4483 Impressions

    16 Retweets

    56 Likes

    13 Bookmarks

    1 Reply

    0 Quotes

  13. CVE-2026-62911 Enables Pre-Auth RCE on Exchange Server - SOC Prime - https://t.co/sgZ82q7bn7 #GoogleAlerts

    @yz9yt

    1 Sept 2026

    51 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. 🚨 CVE-2026-62911 - Microsoft Exchange Server Pre-Auth RCE PoC Released - Orange Tsai Pwn2Own Berlin 2026 Critical Vulnerability Alert! Microsoft Exchange Server is affected by CVE-2026-62911. 🔍 Identify Targets via ZoomEye: Search Dork: app="Exchange Server" Exposure: 11

    @zoomeyebot

    1 Sept 2026

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 🚨 CVE-2026-62911 - Microsoft Exchange Server Pre-Auth RCE PoC Released - Orange Tsai Pwn2Own Berlin 2026 Critical Vulnerability Alert! Microsoft Exchange Server is affected by CVE-2026-62911. 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-62911" Search Dork: h

    @zoomeyebot

    1 Sept 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🚨 CVE-2026-62911 - Microsoft Exchange Server Pre-Auth RCE PoC Released - Orange Tsai Pwn2Own Berlin 2026 Critical Vulnerability Alert! Microsoft Exchange Server is affected by CVE-2026-62911. 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-62911" Search Dork: h

    @zoomeyebot

    1 Sept 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. 🚨 CVE-2026-62911 - Microsoft Exchange Server Pre-Auth RCE PoC Released - Orange Tsai Pwn2Own Berlin 2026 Critical Vulnerability Alert! Microsoft Exchange Server is affected by CVE-2026-62911. 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-62911" Search Dork: h

    @zoomeyebot

    1 Sept 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. CVE-2026-62911 Exchange Server Pre-Auth RCE PoC Released - https://t.co/Z9bsEqgjZj

    @moton

    1 Sept 2026

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. 16 new OPEN, 29 new PRO (16 + 13) Microsoft Exchange Server (CVE-2026-62911), Mennekes Amtron (CVE-2026-8979, CVE-2026-8980), Fake RMM Activity, TA569, Lumma Stealer, XWorm https://t.co/p5hiinCucg https://t.co/5eVkaOWlCB

    @ET_Labs

    28 Aug 2026

    549 Impressions

    1 Retweet

    4 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  20. boh starred hypnguyen1209/CVE-2026-62911 on Github https://t.co/giSrzpoSNE

    @0xbfho

    28 Aug 2026

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations