PT-2026-70598 · Microsoft · Exchange Server

CVE-2026-62911

·

Published

2026-08-11

·

Updated

2026-09-09

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Exchange Server 2016 Microsoft Exchange Server 2019 Microsoft Exchange Server Subscription Edition
Description An authentication bypass by capture-replay allows an authorized attacker to elevate privileges over a network. The issue occurs when authentication material is accepted in a context where stronger channel binding should prevent credential replay or relay-style abuse. A successful exploit allows an attacker to impersonate users and take control of all Exchange mailboxes, enabling them to read emails, download attachments, and send messages as legitimate users. Approximately 21,899 internet-exposed servers were identified as vulnerable, with significant concentrations in the United States (6,200) and Germany (5,100), where roughly 85% of on-premises servers remained affected.
Recommendations Install the Microsoft security updates released in August 2026 for all affected versions. For Exchange Server 2016 and 2019, ensure enrollment in the Extended Security Updates (ESU) program to receive the necessary security patches. Restrict unnecessary internet exposure and limit access to administrative endpoints. Review Exchange and IIS authentication logs, monitor for abnormal mailbox access, and inspect for suspicious inbox forwarding rules or unexpected mailbox delegations.

Exploit

Fix

RCE

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-13469
CVE-2026-62911
ZDI-26-534
ZDI-26-535
ZDI-26-538

Affected Products

Exchange Server