<< Back
CVE Number Vulnerability Product Severity Date
CVE-2026-62911 Microsoft Exchange Server Elevation of Privilege Vulnerability Microsoft Exchange Server Critical 01-09-2026

Technical Information

An authenticated attacker could exploit an authentication bypass through capture-replay in Microsoft Exchange Server to elevate privileges over the network and take over Exchange user mailboxes, enabling access to emails and attachments.

Patch release date: Aug 11, 2026
Further information on this vulnerability is available at : CVE-2026-62911

Affected Software

Microsoft Exchange Server 2016 Cumulative Update 23,
Microsoft Exchange Server Subscription Edition RTM,
Microsoft Exchange Server 2019 Cumulative Update 15,
Microsoft Exchange Server 2019 Cumulative Update 14