Thousands of Exchange Servers Exposed to Auth-Bypass Flaw CVE-2026-62911

Share:

Microsoft has patched CVE-2026-62911, an authentication-bypass flaw in on-premises Microsoft
Exchange Server that, if exploited, could let an attacker take over the mailboxes of every Exchange
user, reading and sending email and downloading attachments. Microsoft rates the issue Critical
(CVSS 8.0) and originally judged exploitation less likely, but a working proof-of-concept has since been
published, with the Dutch and German national CERTs warning it enables remote takeover and that
easily usable exploit code is now online. The Shadowserver Foundation counted more than 21,000
unpatched Exchange servers on 31 August, and CERT-Bund reported that around 85 percent of
German on-premises Exchange servers were still vulnerable. Organisations running Exchange Server
2016, 2019 or Subscription Edition should apply the August 2026 security update immediately and
check their servers for signs of mailbox abuse.

1. Vulnerability Details

CVE ID – CVE-2026-62911
CVSS SCORE – 8.0 (CVSS:3.1, Microsoft; Max Severity Critical) AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EXPLOIT STATUS – Patched 11 Aug 2026. Microsoft assessed exploitation ‘Less Likely’ at publication (not
exploited, not publicly disclosed); a public PoC has since appeared (CERT-Bund, NCSC-NL).
Not in CISA KEV at time of writing.

CVE-2026-62911 is an Authentication Bypass by Capture-replay (CWE-294) in Microsoft Exchange Server. Microsoft classifies it as an Elevation of Privilege issue in which an attacker replays captured authentication material to elevate privileges over the network. Per Microsoft’s guidance, a successful attacker could take over the mailboxes of all Exchange users, reading and sending email and downloading attachments. It was reported by Orange Tsai (@orange_8361) of DEVCORE via the Trend Zero Day Initiative.

2. Affected Products

  • Microsoft Exchange Server 2016 (security updates only via the Extended Security Updates programme).
  • Microsoft Exchange Server 2019 (security updates only via the Extended Security Updates programme).
  • Microsoft Exchange Server Subscription Edition.
  • Fix: apply Microsoft’s August 2026 Exchange Server security update (released 11 Aug 2026).

3. Exploitation & Exposure Status

A patch has been available since 11 August, but exposure remains widespread and a working exploit is now public.

  • Public proof-of-concept CERT-Bund and NCSC-NL report that a PoC exploit has been published; NCSC-NL states that easily usable exploit code is online and both CERTs describe it as enabling remote system takeover.
  • Widespread exposure The Shadowserver Foundation counted at least 21,899 unpatched Exchange servers on 31 August 2026 (top United States ~6,200 and Germany ~5,100) and reports daily. CERT-Bund said around 85 percent of German on-premises Exchange servers were still vulnerable and has been notifying operators since 14 August.

4. Recommendations

  • Apply Microsoft’s August 2026 Exchange Server security update for CVE-2026-62911 immediately across all on-premises Exchange Server 2016, 2019 and Subscription Edition servers; prioritise internet-facing servers given the public PoC and mass exposure.
  • For Exchange Server 2016 and 2019, which receive fixes only through the Extended Security Updates programme, confirm ESU enrolment so the update applies, restrict these servers to internal-only access, and plan migration or replacement as NCSC-NL advises.
  • Reduce exposure while patching: place Exchange behind a reverse proxy or web application firewall, restrict external access to OWA, ECP and other web endpoints, and enforce multi-factor authentication; because the flaw requires user interaction, pair this with user awareness.
  • Hunt for exploitation and mailbox abuse: review Exchange and authentication logs for capture-replay or token-reuse anomalies, unexpected privilege changes, and unauthorised mailbox access such as new inbox or forwarding rules, bulk reads or attachment downloads, and mail sent on users’ behalf.
  • Confirm patch status against Shadowserver’s daily ‘Vulnerable Exchange’ reporting for your IP ranges, and track Microsoft’s advisory and the NVD entry for any escalation of the exploitation assessment.

5. Sources

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62911
  • https://www.ncsc.nl/alerts/ernstige-kwetsbaarheden-in-microsoft-exchange-server
  • https://bsky.app/profile/shadowserver.bsky.social/post/3muhahrqamk2l
  • https://social.bund.de/@certbund/117171896801475447

Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn

No related posts found.

Ampcus Cyber
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Talk to an expert