// Microsoft AzureCRITICAL
CVE-2026-62911, a critical authentication bypass vulnerability in Microsoft Exchange Server disclosed in August 2026, affects over 21,000 unpatched servers globally. The flaw enables NTLM credential relay attacks on the MRSProxy endpoint, allowing unauthenticated attackers to bypass authentication and, when chained with additional vulnerabilities, achieve pre-authentication remote code execution. A public proof-of-concept has been released, and patches are available from Microsoft but adoption remains slow.
- Over 21,000 Microsoft Exchange Servers Remain Exposed to Active (opens in a new tab)
- PoC Released for Microsoft Exchange CVE-2026-62911 Pre-Auth RCE (opens in a new tab)
- Nearly 22,000 Microsoft Exchange servers vulnerable to hijack at(opens in a new tab)
- Nearly 22,000 Exchange servers face complete mailbox takeover ri(opens in a new tab)
- Nearly 22,000 Microsoft Exchange servers remain exposed to criti(opens in a new tab)
- 21,000+ Microsoft Exchange Servers Remain Exposed to Active CVE-(opens in a new tab)
// Get alerts for Microsoft Azure