FR
live
tag

#microsoft-exchange

A capture-replay auth bypass leaves 22,000 Exchange servers exposed

Disclosed on August 11, 2026, CVE-2026-62911 lets an attacker with some access replay a captured authentication to elevate privileges on Microsoft Exchange, and a public PoC is already circulating. Nearly 22,000 servers were still exposed at the end of August; if you are on Exchange 2016 without ESU, the fix is not an option — migration is.

Type at least two characters.

navigate open esc dismiss