AI description
CVE-2026-62911 is an authentication bypass vulnerability affecting Microsoft Exchange Server, specifically versions 2016, 2019, and Subscription Edition. This flaw, categorized as a capture-replay authentication bypass, allows an authorized attacker to elevate privileges over a network. It was publicly demonstrated as part of a successful Microsoft Exchange attack at Pwn2Own Berlin 2026. The vulnerability enables an attacker to intercept authentication material and then replay it to gain higher-privileged access to Exchange resources. This can lead to an attacker taking over user mailboxes, allowing them to read or send emails and download attachments.
- Description
- Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- Source
- secure@microsoft.com
- NVD status
- Modified
- Products
- exchange_server, exchange_server_subscription_edition
CVSS 3.1
- Type
- Secondary
- Base score
- 8
- Impact score
- 5.9
- Exploitability score
- 2.1
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
- secure@microsoft.com
- CWE-294
- Hype score
- Not currently trending
🚨 Critical Exchange Authentication Bypass (#CVE-2026-62911) Threatens 22,000 Servers: A GRC & Patching Emergency + Video -Prediction: 📈 2 Positive | 📉 3 Negative https://t.co/Xsa86mQqcz Educational Purposes!
@UndercodeUpdate
6 Sept 2026
39 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Cisco ya parchó la CVE-2026-20212 en Nexus 9000 y ahí tenés el contraste con lo que Chema viene marcando: cuando una debilidad queda expuesta, el tiempo juega para el atacante. En Exchange pasó algo parecido con CVE-2026-62911. Una PoC pública y 21.899 servidores todavía
@FedeJoelH
5 Sept 2026
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 22,000 Microsoft Exchange servers are STILL exposed to CVE-2026-62911 — a critical auth bypass flaw (CVSS 8.0). Exploit code is already public. Patch guide + detection commands here 👇 https://t.co/QMNMmywsTr #CyberSecurity #CVE https://t.co/PU3PQoVM1m
@Xpert4Cyber
5 Sept 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
【Vulnerability Disclosure | CVE Spotlight】 😱Exchange Server Authentication Flaw Chain Can Lead to SYSTEM-Level Access (CVE-2026-62911) A high-severity authentication bypass and privilege escalation vulnerability, CVE-2026-62911 (CVSS 8.0), has been disclosed in Microsoft
@hackprove_
4 Sept 2026
113 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)(約2万2,000台のMicrosoft Exchangeサーバーが重大な脆弱性CVE-2026-62911に未対応) #HelpNetSecurity (Sep 2) https://t.co/Jl2G2gFPD0
@foxbook
3 Sept 2026
230 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) - https://t.co/FdZZBkoKZb - @Shadowserver- #MicrosoftExchange #CVE #vulnerability #exploit #Cybersecurity #CyberSecurityNews #SecurityNews
@helpnetsecurity
2 Sept 2026
658 Impressions
2 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911): Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans… https://t.co/BG2y0yipQ
@shah_sheikh
2 Sept 2026
66 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔴 CVE-2026-62911 — Microsoft Exchange at risk Public PoC is now available while 21,899 Internet-facing Exchange servers remain vulnerable. No confirmed mass exploitation yet — https://t.co/Z17ChEWLTC #CVE #CVE202662911 #MicrosoftExchange #Exchange #PoC #CyberSecurity #I
@stem__shop
2 Sept 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Exchange Serverの事前認証RCEの概念実証(PoC)であるCVE-2026-62911が公開されました CVE-2026-62911 Exchange Server Pre-Auth RCE PoC Released #DailyCyberSecurity (Sep 1) https://t.co/qWM2gUPgjj
@foxbook
2 Sept 2026
262 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
⚠️ URGENT: 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911! 🛡️ This critical authentication-bypass vulnerability (CVSS 8.0) allows attackers to seize control of enterprise email infrastructure. Shadowserver Foundation reports 21,899 unique IPs
@mazin_dr38737
1 Sept 2026
73 Impressions
3 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 [MASS EXPOSURE] — NEARLY 22,000 MICROSOFT EXCHANGE SERVERS ARE STILL INTERNET-EXPOSED AND VULNERABLE TO A MAILBOX-HIJACK FLAW Shadowserver counted **21,899 exposed Exchange servers** still vulnerable to CVE-2026-62911 — including roughly 6,200 in the U.S. and 5,100 in G
@XQOPTRX
1 Sept 2026
98 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ 21,000+ Microsoft Exchange Servers Remain Exposed to Active CVE-2026-62911 Exploitation Details: https://t.co/MA2JPNX1Ym Nearly 22,000 Microsoft Exchange servers worldwide are still running unpatched for CVE-2026-62911, a critical authentication-bypass vulnerability that
@The_Cyber_News
1 Sept 2026
4483 Impressions
16 Retweets
56 Likes
13 Bookmarks
1 Reply
0 Quotes
CVE-2026-62911 Enables Pre-Auth RCE on Exchange Server - SOC Prime - https://t.co/sgZ82q7bn7 #GoogleAlerts
@yz9yt
1 Sept 2026
51 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-62911 - Microsoft Exchange Server Pre-Auth RCE PoC Released - Orange Tsai Pwn2Own Berlin 2026 Critical Vulnerability Alert! Microsoft Exchange Server is affected by CVE-2026-62911. 🔍 Identify Targets via ZoomEye: Search Dork: app="Exchange Server" Exposure: 11
@zoomeyebot
1 Sept 2026
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-62911 - Microsoft Exchange Server Pre-Auth RCE PoC Released - Orange Tsai Pwn2Own Berlin 2026 Critical Vulnerability Alert! Microsoft Exchange Server is affected by CVE-2026-62911. 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-62911" Search Dork: h
@zoomeyebot
1 Sept 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-62911 - Microsoft Exchange Server Pre-Auth RCE PoC Released - Orange Tsai Pwn2Own Berlin 2026 Critical Vulnerability Alert! Microsoft Exchange Server is affected by CVE-2026-62911. 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-62911" Search Dork: h
@zoomeyebot
1 Sept 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-62911 - Microsoft Exchange Server Pre-Auth RCE PoC Released - Orange Tsai Pwn2Own Berlin 2026 Critical Vulnerability Alert! Microsoft Exchange Server is affected by CVE-2026-62911. 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-62911" Search Dork: h
@zoomeyebot
1 Sept 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-62911 Exchange Server Pre-Auth RCE PoC Released - https://t.co/Z9bsEqgjZj
@moton
1 Sept 2026
31 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
16 new OPEN, 29 new PRO (16 + 13) Microsoft Exchange Server (CVE-2026-62911), Mennekes Amtron (CVE-2026-8979, CVE-2026-8980), Fake RMM Activity, TA569, Lumma Stealer, XWorm https://t.co/p5hiinCucg https://t.co/5eVkaOWlCB
@ET_Labs
28 Aug 2026
549 Impressions
1 Retweet
4 Likes
0 Bookmarks
0 Replies
1 Quote
boh starred hypnguyen1209/CVE-2026-62911 on Github https://t.co/giSrzpoSNE
@0xbfho
28 Aug 2026
71 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2016:-:*:*:*:*:*:*",
"matchCriteriaId": "8039FBA1-73D4-4FF2-B183-0DCC961CBFF7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_1:*:*:*:*:*:*",
"matchCriteriaId": "56728785-188C-470A-9692-E6C7235109CA",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_10:*:*:*:*:*:*",
"matchCriteriaId": "63E362CB-CF75-4B7E-A4B1-D6D84AFCBB68",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_11:*:*:*:*:*:*",
"matchCriteriaId": "9BE04790-85A2-4078-88CE-1787BC5172E7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_12:*:*:*:*:*:*",
"matchCriteriaId": "CCF101BE-27FD-4E2D-A694-C606BD3D1ED7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_13:*:*:*:*:*:*",
"matchCriteriaId": "4DF5BDB5-205D-4B64-A49A-0152AFCF4A13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_14:*:*:*:*:*:*",
"matchCriteriaId": "55284CF7-0D04-4216-83FE-4B1F9CA94207",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_15:*:*:*:*:*:*",
"matchCriteriaId": "CA2CE223-AA49-49E6-AC32-59270EFF55AD",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_16:*:*:*:*:*:*",
"matchCriteriaId": "4830D6A9-AF74-480C-8F69-8648CD619980",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_17:*:*:*:*:*:*",
"matchCriteriaId": "079E1E3F-FF25-4B0D-AC98-191D6455A014",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_18:*:*:*:*:*:*",
"matchCriteriaId": "29805EC7-6403-44B9-91EC-109C087E98EB",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_19:*:*:*:*:*:*",
"matchCriteriaId": "28FCA0E8-7D27-4746-9731-91B834CA3E64",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_2:*:*:*:*:*:*",
"matchCriteriaId": "996163E7-6F3F-4D3B-AEA4-62A7F7E1F54D",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_20:*:*:*:*:*:*",
"matchCriteriaId": "19C1EE0C-B8DD-4B91-BE4B-1C42D72FB718",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_21:*:*:*:*:*:*",
"matchCriteriaId": "3BE427A4-B0C2-4064-8234-29426325C348",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_22:*:*:*:*:*:*",
"matchCriteriaId": "449CE85B-E599-44D3-A7C1-5133F6A55E86",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_3:*:*:*:*:*:*",
"matchCriteriaId": "FE401B0A-DDE4-4A36-8E27-6DB14E094BE2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_4:*:*:*:*:*:*",
"matchCriteriaId": "450319C4-7C8F-43B7-B7F8-80DA4F1F2817",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_5:*:*:*:*:*:*",
"matchCriteriaId": "23015889-48AF-40A5-862F-290E73A54E77",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_6:*:*:*:*:*:*",
"matchCriteriaId": "4FC34516-D7E7-4AD9-9B45-5474831548E0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_7:*:*:*:*:*:*",
"matchCriteriaId": "5211792E-5292-41C0-B7E9-8AA63EC606EE",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_8:*:*:*:*:*:*",
"matchCriteriaId": "075E907F-AF2F-4C31-86C7-51972BE412A1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_9:*:*:*:*:*:*",
"matchCriteriaId": "69AF19DC-3D65-49A8-A85F-511085CDF27B",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2019:-:*:*:*:*:*:*",
"matchCriteriaId": "40D8A6DB-9225-4A3F-AD76-192F6CCCF002",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_1:*:*:*:*:*:*",
"matchCriteriaId": "051DE6C4-7456-4C42-BC51-253208AADB4E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_10:*:*:*:*:*:*",
"matchCriteriaId": "B4185347-EEDD-4239-9AB3-410E2EC89D2A",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_11:*:*:*:*:*:*",
"matchCriteriaId": "435343A4-BF10-461A-ABF2-D511A5FBDA75",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_12:*:*:*:*:*:*",
"matchCriteriaId": "B23C8E3E-5243-4DA6-B9AA-F6053084B55E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_13:*:*:*:*:*:*",
"matchCriteriaId": "583745C7-B802-4CBE-BD88-B5B9AF9B5371",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_2:*:*:*:*:*:*",
"matchCriteriaId": "EE320413-D2C9-4B28-89BF-361B44A3F0FF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_3:*:*:*:*:*:*",
"matchCriteriaId": "104F96DC-E280-4E0A-8586-B043B55888C2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_4:*:*:*:*:*:*",
"matchCriteriaId": "73B3B3FE-7E85-4B86-A983-2C410FFEF4B8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_5:*:*:*:*:*:*",
"matchCriteriaId": "8A9FB275-7F17-48B2-B528-BE89309D2AF5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_6:*:*:*:*:*:*",
"matchCriteriaId": "D4AB3C25-CEA8-4D66-AEE4-953C8B17911A",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_7:*:*:*:*:*:*",
"matchCriteriaId": "36CE5C6D-9A04-41F5-AE7C-265779833649",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_8:*:*:*:*:*:*",
"matchCriteriaId": "44ECF39A-1DE1-4870-A494-06A53494338D",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_9:*:*:*:*:*:*",
"matchCriteriaId": "71CDF29B-116B-4DE2-AFD0-B62477FF0AEB",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:exchange_server_subscription_edition:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E11586E4-99CF-427F-829F-3365F83F94D5",
"versionEndExcluding": "15.02.2562.046",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]