// Microsoft 365HIGH
A public proof-of-concept was released on September 1, 2026 for CVE-2026-62911, an authentication-bypass and file-write vulnerability chain in Microsoft Exchange Server affecting versions 2016 CU23, 2019 CU14/CU15, and Subscription Edition. The PoC details exploitation via NTLM relay against the MRSProxy service, enabling pre-authentication remote code execution as SYSTEM. Microsoft released patches in August 2026; organizations must immediately apply fixes and reduce external exposure to Exchange services.
- PoC Released for Microsoft Exchange CVE-2026-62911 Pre-Auth RCE (opens in a new tab)
- Nearly 22,000 Microsoft Exchange servers vulnerable to hijack at(opens in a new tab)
- Over 21,000 Microsoft Exchange Servers Remain Exposed to Active (opens in a new tab)
- Public PoC Released for Microsoft Exchange Server Pre-auth RCE V(opens in a new tab)
- Nearly 22,000 Exchange servers face complete mailbox takeover ri(opens in a new tab)
- Nearly 22,000 Microsoft Exchange servers remain exposed to criti(opens in a new tab)
// Get alerts for Microsoft 365