CVE-2026-62911
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- Affected products
- Exchange Server
- Microsoft Exchange Server
- = 2016, 2019
- Microsoft Exchange Server Subscription Edition
- < 15.02.2562.046
- CVSS 3.1
- 8.0 HIGH
- EPSS
- 0.7% (51th percentile)
- Weakness
- CWE-294
- NVD status
- Analyzed
- Published
- 2026-08-11
CVE-2026-62911 at NVD
1 known exploit for CVE-2026-62911
Proof-of-concept code and exploit modules indexed by Sploitus