CVE-2026-62911Disclosure(microsoft / exchange_server)

CRITICALCVSS 8.0 · HIGH

Exploitation observed; activity peaked at 26 mentions and remains active

Immediate actions

  • Patch microsoft exchange_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-294

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • exchange_server
  • exchange_server_subscription_edition

Threat summary

  • Active exploitation appears in 7 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 105 mentions across 21 observed days

What's happening

  • Active exploitation reported across 7 signals
  • Exploit tool or code specified in 19 signals
  • PoC mentioned or linked in 38 signals
  • Patch or workaround mentioned in 31 signals
  • Technical details provided in 66 signals
  • Disclosure: 27 classified signals
  • General: 25 classified signals
  • Peaked 4d ago at 26 mentions (2026-09-09); latest day: 1
  • 105 total mentions across 21 days

Affected systems

Vendors
Products
exchange_serverexchange_server_subscription_edition

2 versions affected across 2 products

Deep dive

Activity timeline105 mentions / 21d
07132026Mentions · 2026-08-13: 1Mentions · 2026-08-15: 1Mentions · 2026-08-16: 1Mentions · 2026-08-17: 1Mentions · 2026-08-24: 1Mentions · 2026-08-25: 1Mentions · 2026-08-26: 6Mentions · 2026-08-27: 4Mentions · 2026-08-28: 2Mentions · 2026-09-01: 22Mentions · 2026-09-02: 22Mentions · 2026-09-03: 7Mentions · 2026-09-04: 1Mentions · 2026-09-05: 1Mentions · 2026-09-06: 2Mentions · 2026-09-08: 2Mentions · 2026-09-09: 26Mentions · 2026-09-10: 1Mentions · 2026-09-14: 1Mentions · 2026-09-15: 1Mentions · 2026-09-16: 1PoC Mentioned / Linked · 2026-08-24: 1PoC Mentioned / Linked · 2026-08-25: 1PoC Mentioned / Linked · 2026-08-26: 4PoC Mentioned / Linked · 2026-08-27: 3PoC Mentioned / Linked · 2026-09-01: 10PoC Mentioned / Linked · 2026-09-02: 10PoC Mentioned / Linked · 2026-09-03: 3PoC Mentioned / Linked · 2026-09-06: 1PoC Mentioned / Linked · 2026-09-08: 1PoC Mentioned / Linked · 2026-09-09: 1PoC Mentioned / Linked · 2026-09-10: 1PoC Mentioned / Linked · 2026-09-15: 1PoC Mentioned / Linked · 2026-09-16: 1Exploit Tool / Code · 2026-08-24: 1Exploit Tool / Code · 2026-08-25: 1Exploit Tool / Code · 2026-08-26: 2Exploit Tool / Code · 2026-08-27: 3Exploit Tool / Code · 2026-09-01: 5Exploit Tool / Code · 2026-09-02: 3Exploit Tool / Code · 2026-09-03: 1Exploit Tool / Code · 2026-09-08: 1Exploit Tool / Code · 2026-09-09: 1Exploit Tool / Code · 2026-09-15: 1Active Exploitation · 2026-08-17: 1Active Exploitation · 2026-09-01: 3Active Exploitation · 2026-09-02: 3Patch / Workaround · 2026-08-13: 1Patch / Workaround · 2026-08-15: 1Patch / Workaround · 2026-08-16: 1Patch / Workaround · 2026-08-17: 1Patch / Workaround · 2026-08-27: 1Patch / Workaround · 2026-09-01: 8Patch / Workaround · 2026-09-02: 9Patch / Workaround · 2026-09-03: 3Patch / Workaround · 2026-09-04: 1Patch / Workaround · 2026-09-05: 1Patch / Workaround · 2026-09-08: 1Patch / Workaround · 2026-09-14: 1Patch / Workaround · 2026-09-15: 1Patch / Workaround · 2026-09-16: 1Technical Details · 2026-08-13: 1Technical Details · 2026-08-15: 1Technical Details · 2026-08-16: 1Technical Details · 2026-08-17: 1Technical Details · 2026-08-24: 1Technical Details · 2026-08-25: 1Technical Details · 2026-08-26: 4Technical Details · 2026-08-27: 4Technical Details · 2026-09-01: 16Technical Details · 2026-09-02: 15Technical Details · 2026-09-03: 4Technical Details · 2026-09-04: 1Technical Details · 2026-09-05: 1Technical Details · 2026-09-06: 1Technical Details · 2026-09-08: 1Technical Details · 2026-09-09: 10Technical Details · 2026-09-10: 1Technical Details · 2026-09-15: 1Technical Details · 2026-09-16: 108-1308-1608-2408-2608-2809-0209-0409-0609-0909-1409-16
Signal classification7 categories
Disclosure
2725.7%
General
2523.8%
PoC
2422.9%
Patch
2019.0%
Active Exploitation
54.8%
Exploit
32.9%
Referenced assets77 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-131
Patch1
2026-08-151
Patch1
2026-08-161
Patch1
2026-08-171
Disclosure1
2026-08-241
PoC1
2026-08-251
PoC1
2026-08-266
Exploit1False Positive1General1PoC3
2026-08-274
Disclosure1Patch1PoC2
2026-08-282
General2
2026-09-0122
Active Exploitation2Disclosure3General4Patch7PoC6
2026-09-0222
Active Exploitation3Disclosure7Exploit1General1Patch5PoC5
2026-09-037
Disclosure3Exploit1General1Patch2
2026-09-041
Disclosure1
2026-09-051
Patch1
2026-09-062
Disclosure1PoC1
2026-09-082
General1PoC1
2026-09-0926
Disclosure10General15PoC1
2026-09-101
PoC1
2026-09-141
Patch1
2026-09-151
PoC1
2026-09-161
PoC1
Full discourse20 posts
  • H4x0r.DZ 🇰🇵@h4x0r_dz
    PoC

    Pre-auth RCE on Microsoft Exchange Server. No credentials needed. https://github.com/hypnguyen1209/cve-2026-62911

    Post summary

    The post announces a pre‑authentication remote code execution flaw (CVE‑2026‑62911) in Microsoft Exchange Server and provides a GitHub repository containing a proof‑of‑concept exploit, with no mention of active exploitation, patches, or false‑positives.

    777037425634.5K
    83.6K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 CVE-2026-62911 için Microsoft Exchange Server'a yönelik bir PoC yayınlandı. Bu açık, kimlik doğrulama atlatma yoluyla yetki yükseltmeye ve saldırı zincirinin devamında uzaktan kod çalıştırmaya kadar gidebiliyor. https://github.com/hypnguyen1209/cve-2026-62911

    Post summary

    A proof‑of‑concept for CVE‑2026‑62911, targeting Microsoft Exchange Server, has been released showing authentication bypass, privilege escalation, and remote code execution, but no active exploitation or patch information is provided.

    260118917444.9K
    2.4K followersView on X
  • Ryx@PadhiyarRushi
    PoC

    Public PoC for the Exchange pre-auth chain (CVE-2026-62911 / related) is circulating. Orange Tsai demonstrated the full path at Pwn2Own Berlin (SYSTEM, $200k). The published Python PoC automates the MRSProxy + session issues into a working unauthenticated-to-SYSTEM sequence on unpatched on-prem Exchange. Internet-facing Exchange that missed the August updates is in a bad place right now. https://www.decryptiondigest.com/blog/exchange-cve-2026-62911-pre-auth-rce-patch-now #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #Exchange #RCE

    Post summary

    A public Python PoC for the CVE-2026-62911 Exchange pre-auth RCE chain (demonstrated at Pwn2Own Berlin) is circulating, with August patches available but unpatched on-prem systems at risk.

    0331126638.5K
    930 followersView on X
  • kokumօtօ@__kokumoto
    PoC

    Exchange Serverの無認証遠隔コード実行CVE-2026-62911に対応するPoC(攻撃の概念実証コード)が公表された。脆弱性はPwn2Own Berlin 2026で提示されていたもの。SYSTEM権限での任意コマンド実行。技術的詳細あり。 https://securityonline.info/cve-2026-62911-exchange-server-pre-auth-rce-poc/

    Post summary

    A proof‑of‑concept for CVE-2026‑62911, a remote code execution vulnerability in Exchange Server, has been released with technical details and a public link.

    019091666.4K
    7.8K followersView on X
  • Terrance DeJesus@_xDeJesus
    PoC

    The feed today is already a hot mess. Log4j2 shenanigans - https://github.com/apache/logging-log4j2/issues/4255 Next.js Windows RCE PoC - https://github.com/rafabd1/CVE-2026-75604-poc Exchange CVE-2026-62911 PoC is public. Microsoft scored it as an auth bypass. The PoC (and Pwn2Own) treat it as pre-auth RCE. https://github.com/hypnguyen1209/CVE-2026-62911 And Microsoft bundled Intune Remote Help into M365 E3/E5. Seems ripe for phishing abuse. https://techcommunity.microsoft.com/blog/microsoftintuneblog/advanced-microsoft-intune-capabilities-now-available-in-microsoft-365-e3-and-e5/4529335 am I missing anything? lol

    Post summary

    The post shares PoC code links for Next.js Windows RCE and Exchange CVE-2026-62911, describing RCE and auth bypass details, but does not report active exploitation or patches.

    421181517.0K
    948 followersView on X
  • Cyber Security News@The_Cyber_News
    Active Exploitation

    ⚠️ 21,000+ Microsoft Exchange Servers Remain Exposed to Active CVE-2026-62911 Exploitation Details: https://cybersecuritynews.com/exchange-servers-remain-exposed-2026-62911/ Nearly 22,000 Microsoft Exchange servers worldwide are still running unpatched for CVE-2026-62911, a critical authentication-bypass vulnerability that attackers can exploit to seize control of enterprise email infrastructure. According to daily internet-wide scans published by the Shadowserver Foundation, exactly 21,899 unique IP addresses were flagged as vulnerable as of August 31, 2026, underscoring how slowly organizations are responding to one of this year's most consequential Patch Tuesday disclosures. CVE-2026-62911 is classified as an authentication bypass by capture-replay flaw, tracked under CWE-294, and carries a CVSS score of 8.0. #cybersecuritynews

    Post summary

    Nearly 22,000 unpatched Microsoft Exchange servers remain exposed to CVE-2026-62911, an authentication-bypass flaw (CWE‑294, CVSS 8.0) that attackers can exploit, with daily scans confirming ongoing risk; no PoC, exploit tool, or patch information is provided.

    130093198.0K
    74.2K followersView on X
  • Jeff McJunkin@jeffmcjunkin
    PoC

    It's crazy to me that I can kick off a /goal inside Claude Code with the @badsectorlabs Ludus skill and get a fresh, artisanal lab with two Exchange 2019 servers inside for testing https://github.com/hypnguyen1209/cve-2026-62911 Ludus is love. Ludus is life. Use Ludus.

    Post summary

    The post points to a GitHub repository likely containing a PoC for CVE‑2026‑62911 and describes a ready‑made testing lab, but it provides no exploit code, patch info, or evidence of real‑world exploitation.

    216166545.8K
    12.2K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-62911 Vendor: Microsoft Product: Microsoft Exchange Server 2016 Description: Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. Link: https://github.com/hypnguyen1209/cve-2026-62911 #dbugs_vuln

    Post summary

    A proof‑of‑concept exploit for CVE-2026-62911, targeting authentication bypass in Microsoft Exchange Server 2016, has been released on GitHub.

    116074325.1K
    3.6K followersView on X
  • Netlas.io@Netlas_io
    PoC

    CVE-2026-62911: Pre-auth RCE in Microsoft Exchange with public PoC, 8.0 rating ‍🔥 Disclosed at the August Patch Tuesday, this pre-auth RCE vulnerability allows unauthenticated attackers on local networks to achieve remote code execution as SYSTEM. And now a PoC exists! 👉 https://nt.ls/rnLCg

    Post summary

    CVE-2026-62911 is a pre-authenticaton Remote Code Execution flaw in Microsoft Exchange with an 8.0 CVSS score, and a public proof‑of‑concept has been released to demonstrate the exploitation.

    19031152.5K
    7.7K followersView on X
  • Mike Felch (Stay Ready)@ustayready
    PoC

    RCE on Microsoft Exchange dropped, I haven’t vetted it but plan to soon https://github.com/hypnguyen1209/cve-2026-62911

    Post summary

    A Proof of Concept for CVE‑2026‑62911, an RCE in Microsoft Exchange, has been uploaded to GitHub, though its effectiveness has not yet been verified.

    04022121.8K
    17.5K followersView on X
  • Steven Lim@0x534c
    General

    📬 Is your Exchange Server one of the 22,000 vulnerable to hijack attacks ? Bleeping Computer: Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks Link: https://www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/ KQL Check (CVE-2026-62911)👇 https://detections.ai/share/rule/aLyyEIcS #VulnerabilityManagement https://t.co/rmjvxsEv8m

    Post summary

    The post alerts that nearly 22,000 Microsoft Exchange servers are susceptible to hijack attacks and links to a detection rule for CVE-2026-62911, but offers no proof of exploit, patch information, or technical depth.

    02021142.0K
    7.7K followersView on X
  • CERT@certlv
    Patch

    ‼️Brīdinājums! Konstatēta augstas bīstamības Microsoft Exchange Server ievainojamība (CVE-2026-62911). 🛡️ Aicinām pēc iespējas ātrāk instalēt atbilstošo Microsoft drošības atjauninājumu un pārliecināties, ka Exchange Server ir atjaunināts. Vairāk: https://www.cert.lv/lv/2026/09/microsoft-exchange-server-ievainojamiba-cve-2026-62911 https://t.co/DAWnmkmCjS

    Post summary

    A warning has been issued for CVE-2026-62911, highlighting its high severity on Microsoft Exchange Server and strongly recommending immediate installation of the relevant Microsoft security update.

    01401623.2K
    5.7K followersView on X
  • IT-Connect.fr@ITConnect_fr
    Patch

    🛑 22 000 C'est le nombre de serveurs Exchange exposés sur le Web et potentiellement vulnérables à la faille CVE-2026-62911. Il s'agit d'une faille patchée en août 2026 par Microsoft. Plus d'infos par ici : - https://www.it-connect.fr/microsoft-exchange-cve-2026-62911/ #exchange #microsoft #infosec https://t.co/W05unV4hms

    Post summary

    The tweet notes that 22,000 Exchange servers are exposed and potentially vulnerable to CVE-2026-62911, which has been patched by Microsoft in August 2026, with a link for further details.

    1901361.8K
    11.7K followersView on X
  • mRr3b00t@UK_Daniel_Card
    General

    at least it's not Friday: CVE-2026-62911 #Exchange #Vulnerabilities #Exploits

    Post summary

    A brief tweet merely lists CVE-2026-62911 with no additional context, indicating a general mention of a vulnerability linked to Exchange.

    0201663.9K
    125.8K followersView on X
  • The Shadowserver Foundation@Shadowserver
    General

    We are scanning & reporting daily on vulnerable Microsoft Exchange CVE-2026-62911 (Authentication Bypass by Capture-replay) instances in our Vulnerable Exchange reporting: https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-exchange-server-report/ At least 21899 IPs seen unpatched 2026-08-31, top US (6.2K) & Germany (5.1K) https://t.co/jkiOz3Lvrr

    Post summary

    The post reports daily scanning results for Microsoft Exchange servers affected by CVE‑2026‑62911, providing prevalence statistics but offering no exploitation or mitigation details.

    140941.8K
    22.0K followersView on X
  • Dr. Mazin Al-Busaidi@mazin_dr38737
    Patch

    🚨 URGENT: Microsoft has issued critical security updates for Exchange Server! 🛡️ Major vulnerabilities discovered include Remote Code Execution (RCE), DoS, and Privilege Escalation. The most severe, CVE-2026-62911 (CVSS 8.0), involves a dangerous authentication bypass by capture-replay. Affected versions: ✅ Exchange Server 2016, 2019, & Subscription Edition. تحذير أمني هام: مايكروسوفت تطلق تحديثات طارئة لسد ثغرات خطيرة في Exchange Server قد تؤدي إلى اختراق كامل للأنظمة وتنفيذ أوامر برمجية عن بُعد. يجب التحديث فوراً لحماية بياناتكم من الهجمات! Don't wait—patch your systems now to stay protected! 💻🔒 Full details here: https://cybersecuritynews.com/microsoft-exchange-server-vulnerabilities-rce/ #CyberSecurity #Microsoft #ExchangeServer #InfoSec #PatchTuesday #TechNews #أمن_المعلومات

    Post summary

    Microsoft has released urgent patches for Exchange Server, including CVE‑2026‑62911, which enables remote code execution via authentication bypass; organizations are urged to update immediately.

    07070239
    1.2K followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Active Exploitation

    🚨 Upozorňujeme na aktivní zneužívání zranitelnosti v Microsoft Exchange Server, CVE-2026-62911. Zranitelnost v Mailbox Replication Proxy Service (MRSProxy) umožňuje neautentizovanému útočníkovi s přístupem do lokální sítě spustit libovolný kód s oprávněními SYSTEM. Útok může využívat přesměrování ověřování NTLM a nedostatečnou ochranu HTTP endpointu Exchange k získání vyšších oprávnění a zápisu libovolných souborů na server. Úspěšné zneužití může vést k úplné kompromitaci serveru a přístupu k citlivé podnikové komunikaci a datům. Riziko zvyšuje veřejná dostupnost technických detailů a PoC exploitu. Zranitelné jsou Microsoft Exchange Server 2016 CU23 do verze 15.1.2507.72, Exchange Server 2019 CU14 do verze 15.2.1544.43, Exchange Server 2019 CU15 do verze 15.2.1748.48 a Exchange Server Subscription Edition RTM do verze 15.2.2562.45. 📌Doporučujeme aktualizovat Exchange Server 2016 na verzi 15.1.2507.072 nebo novější, Exchange Server 2019 CU14 na 15.2.1544.044 nebo novější, Exchange Server 2019 CU15 na 15.2.1748.049 nebo novější a Exchange Server Subscription Edition RTM na 15.2.2562.046 nebo novější.

    Post summary

    CVE‑2026‑62911 is actively exploited in Microsoft Exchange Servers via a publicly available PoC; immediate patching to the latest CU is strongly advised.

    050601.4K
    4.3K followersView on X
  • CiberBaur@BotBauR
    Patch

    🚨 Alerta: 22 000 servidores Exchange siguen vulnerables a CVE‑2026‑62911. EE.UU. y Alemania lideran con 6 200 y 5 100 servidores sin parchear. Según escaneos diarios de Shadowserver Foundation, al 2 de septiembre de 2026 todavía hay casi 22 000 instancias sin aplicar el parche crítico que corrige la vulnerabilidad de bypass de autenticación por captura‑replay. #Ciberseguridad #CVE #SeguridadDigital #APT https://www.helpnetsecurity.com/2026/09/02/microsoft-exchange-cve-2026-62911-critical-authentication-bypass-flaw/

    Post summary

    The tweet highlights that about 22,000 Exchange servers remain vulnerable to CVE‑2026‑62911 and stresses the need for the critical patch, without discussing exploitation or proof of concept.

    04061426
    631 followersView on X
  • Zscaler@zscaler
    Patch

    Thousands of on-prem Exchange servers are still exposed after #Microsoft’s fix for CVE-2026-62911. Our latest blog covers what teams should do now — and what to consider long term: https://bit.ly/4j4F3D7 https://t.co/bcUbs58pO5

    Post summary

    The tweet notes that many on-prem Exchange servers remain exposed despite Microsoft's fix for CVE-2026-62911 and directs readers to a blog for guidance, indicating a patch exists but mitigation is still required.

    04060861
    17.9K followersView on X
  • Dr. Mazin Al-Busaidi@mazin_dr38737
    Patch

    ⚠️ URGENT: 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911! 🛡️ This critical authentication-bypass vulnerability (CVSS 8.0) allows attackers to seize control of enterprise email infrastructure. Shadowserver Foundation reports 21,899 unique IPs are still exposed globally. If you haven't patched yet, your organization is at high risk. Patch now! ⚠️ تحذير: أكثر من 21,000 خادم Microsoft Exchange لا تزال معرضة للاختراق بسبب ثغرة CVE-2026-62911 الخطيرة. تسمح هذه الثغرة للمهاجمين بالسيطرة الكاملة على البريد الإلكتروني للمؤسسات. سارع بالتحديث فوراً لحماية بياناتك! Details: https://cybersecuritynews.com/exchange-servers-remain-exposed-2026-62911/ #CyberSecurity #Microsoft #Infosec #PatchTuesday #cybersecuritynews

    Post summary

    The message warns of a widespread COVID‑related patch backlog on Microsoft Exchange, cites the vulnerability’s severity, and urges immediate patching, with no PoC or exploit details provided.

    05040113
    1.2K followersView on X
CPE platform detail38 entries

38 of 38 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2016--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server2019--
Appmicrosoftexchange_server_subscription_edition---

Explore more