CVE-2026-62911 Microsoft Exchange Server Elevation of Privilege Vulnerability
8.0
Analysis on rafaelpfister.ch
- Article · August 31, 2026 CVE-2026-62911: Why 85 Percent of On-Premises Exchange Servers Are Vulnerable and What Is Technically Behind It The BSI reports that around 85 percent of on-premises Exchange servers in Germany are vulnerable to CVE-2026-62911. This article explains the vulnerability technically: MRSProxy, missing Channel Binding, NTLM relay, and Orange Tsai’s Pwn2Own chain, along with context for the figures and the specific recommended actions.
- Article · August 19, 2026 August 2026 Exchange Security Updates: Pwn2Own Vulnerability Fixed, OWA Light Disabled The August SU fixes seven vulnerabilities, including the Exchange exploit demonstrated at Pwn2Own 2026, and permanently disables OWA Light. Microsoft also explains why Exchange SUs are now released monthly and why Exchange SE CU1 is still delayed.
Vendor description
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. Reference data
- Vendor
- Microsoft
- Affected products
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Update 14
- Microsoft Exchange Server 2019 Cumulative Update 15
- Microsoft Exchange Server Subscription Edition RTM
- CVSS 3.1
- 8.0 (HIGH)
- Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C- Weakness type
- CWE-294: Authentication Bypass by Capture-replay
- Published
- August 11, 2026