type: cve ยท created: 2026-09-09 ยท updated: 2026-09-09 ยท tags: [cve, exchange, authentication-bypass, poc, exploitation] ยท confidence: high ยท severity: high ยท affected_sectors: [government, finance, technology, education, healthcare] ยท au_impact: true
CVE-2026-62911
CVE-2026-62911 is an unauthenticated authentication-bypass in Microsoft Exchange Server that allows an attacker to intercept and replay authentication traffic and gain elevated privileges, potentially taking control of every mailbox on the server. It was discovered by Orange Tsai of DEVCORE at Pwn2Own Berlin.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-62911 |
| Type | Unauthenticated authentication bypass (mailbox takeover) |
| PoC | Public working exploit code |
| Advisory escalation | NCSC-NL warns of potential arbitrary code execution |
| KEV | Not yet in CISA KEV at reporting |
| Source | iTnews โ Tier 3/4 |
Three weeks after Microsoft's fix, 382 Australian and 56 New Zealand Exchange servers remained vulnerable as of 31 August 2026 (Shadowserver). The ASD urged organisations running legacy Exchange 2016/2019/Subscription Edition to patch or, where replacement is not possible, segment legacy networks. Microsoft had not confirmed in-the-wild exploitation at the time.
Related Pages
- Hundreds Of Old Vulnerable Exchange Servers Remain In Australia โ the Australian exposure incident