Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3887 articles · 205847 vulns · 37/41 feeds (7d)
← Back to list
8.0
CVE-2026-62911PATCHED
microsoft · exchange_server

Microsoft Exchange Server Elevation of Privilege Vulnerability

Description

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Affected Products

VendorProductVersions
microsoftexchange_server15.01.0.0, 15.02.0.0, 15.02.0.0, 15.02.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
googlegoogle cloudcert_advisory90%
lenovolenovo computercert_advisory90%
microsoftexchange_server_subscription_editioncve_cpe95%
microsoftmicrosoft windows server 2012 r2cert_advisory90%
microsoftmicrosoft exchange server 2019 cumulative updatemitre_affected90%

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62911(vendor-advisory, patch)

Related News (7 articles)

Tier D
Heise Security2d ago
Exchange-Sicherheitslücke: Wegen Proof-of-Concept Angriffe wahrscheinlich
→ No new info (linked only)
Tier B
BSI Advisories17d ago
[NEU] [hoch] Microsoft Exchange Server: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
BSI Advisories17d ago
[NEU] [kritisch] Microsoft Windows Produkte: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR17d ago
Multiples vulnérabilités dans les produits Microsoft (12 août 2026)
→ No new info (linked only)
Tier C
VulDB17d ago
CVE-2026-62911 | Microsoft Exchange Server authentication replay
→ No new info (linked only)
Tier A
Microsoft MSRC18d ago
CVE-2026-62911 Microsoft Exchange Server Elevation of Privilege Vulnerability
→ No new info (linked only)
Tier C
CrowdStrike Blog18d ago
August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs
→ No new info (linked only)
CVSS 3.18.0 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CISA KEV❌ No
Actively exploited❌ No
Patch available
15.01.2507.07215.02.1544.04415.02.1748.04915.02.2562.046
CWECWE-294
PublishedAug 11, 2026
Last enriched18d ago
Trending Score44
Source articles7
Independent6
Info Completeness7/14
Missing: title, description, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-55040EXPKEV
Microsoft SharePoint Server Security Feature Bypass Vulnerability
Trending: 126
HIGHCVE-2026-63520EXPKEV
Microsoft SharePoint Server Remote Code Execution Vulnerability
Trending: 101
CRITICALCVE-2026-69836EXPKEV
Microsoft Entra ID Remote Code Execution Vulnerability
Trending: 58
HIGHCVE-2026-50656EXP
Microsoft Defender Elevation of Privilege Vulnerability
Trending: 51
HIGHCVE-2026-69414
Microsoft Defender Elevation of Privilege Vulnerability
Trending: 40

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 11, 2026
Discovered by ZDM
Aug 11, 2026
Patch Available
Aug 29, 2026