DIRAS TAKE
Urgent: public exploit code exists, so patch quickly; a working exploit is publicly available and fixes are released for the affected Exchange builds.
What is CVE-2026-62911?
An authorized attacker can bypass authentication and elevate privileges in Microsoft Exchange Server, enabling remote privilege escalation across affected cumulative updates; see CVE-2026-62911. The vulnerability impacts Exchange Server 2016 Cumulative Update 23 (15.01.0.0 through before 15.01.2507.072) and several Exchange Server 2019 and Subscription Edition releases listed below. Exploitation requires network access and an authorized account interaction that can be abused via a capture-replay authentication bypass technique.
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Which versions of Microsoft Microsoft Exchange Server 2016 Cumulative Update 23 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Microsoft Exchange Server 2016 Cumulative Update 23 15.x | 15.01.0.0 – before 15.01.2507.072 | 15.01.2507.072 |
| Microsoft Exchange Server 2019 Cumulative Update 14 15.x | 15.02.0.0 – before 15.02.1544.044 | 15.02.1544.044 |
| Microsoft Exchange Server 2019 Cumulative Update 15 15.x | 15.02.0.0 – before 15.02.1748.049 | 15.02.1748.049 |
| Microsoft Exchange Server Subscription Edition RTM 15.x | 15.02.0.0 – before 15.02.2562.046 | 15.02.2562.046 |
Is CVE-2026-62911 being exploited?
Public exploit code is available.
How to fix CVE-2026-62911
- Upgrade Exchange Server 2016 CU23 to 15.01.2507.072 or later.
- Upgrade Exchange Server 2019 CU14 to 15.02.1544.044 or later, or CU15 to 15.02.1748.049 or later as appropriate.
- Upgrade Exchange Server Subscription Edition RTM to 15.02.2562.046 or later.
- If you cannot patch immediately, restrict network exposure of Exchange management and authentication endpoints and monitor logs for anomalous authentication activity.
Frequently asked questions
Is CVE-2026-62911 being actively exploited?
Public exploit code is available for CVE-2026-62911.
Which Microsoft Exchange Server versions are affected by CVE-2026-62911?
Affected builds include Exchange 2016 CU23 versions 15.01.0.0 through before 15.01.2507.072 and multiple Exchange 2019 and Subscription Edition builds listed in the vendor advisory.
Is there a patch for CVE-2026-62911?
Yes; Microsoft published fixes: 15.01.2507.072 for Exchange 2016 CU23 and the fixed builds 15.02.1544.044, 15.02.1748.049, and 15.02.2562.046 for the listed 2019 and Subscription Edition branches.
Does CVE-2026-62911 require authentication?
Yes; exploitation involves an authorized account and a capture-replay technique that elevates privileges over the network.
References
- nvd.nist.gov/vuln/detail/CVE-2026-62911
- cve.org/CVERecord?id=CVE-2026-62911
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62911
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026