// Alert

Microsoft 365 threat report

Microsoft patched six Exchange Server vulnerabilities affecting Exchange Server Subscription Edition, 2019, and 2016 via August 2026 Patch Tuesday. CVE-2026-62913 is a critical remote code execution flaw (CVSS 8.8) exploitable over the network without user interaction via heap-based buffer overflow. CVE-2026-62911 (CVSS 8.0) enables authentication bypass and privilege escalation, demonstrated at Pwn2Own Berlin. Additional flaws include DoS, privilege escalation, spoofing, and authorization bypass impacts.

// Get alerts for Microsoft 365