CVE-2026-62911: Microsoft Exchange Server Elevation of Privilege Vulnerability
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Other sources
Microsoft Exchange Server Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1748.049Patch KB5121574 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2507.072Patch KB5121576 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.2562.046Patch KB5121573 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1544.044Patch KB5121575
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62911?
CVE-2026-62911 has a severity rating of high, with a CVSS score of 8.
How do I fix CVE-2026-62911?
To mitigate CVE-2026-62911, apply the latest security updates provided by Microsoft for Exchange Server.
What systems are affected by CVE-2026-62911?
CVE-2026-62911 affects Microsoft Exchange Server 2019, Microsoft Exchange Server 2016, and Microsoft Exchange Server Subscription Edition.
What type of vulnerability is CVE-2026-62911?
CVE-2026-62911 is an elevation of privilege vulnerability due to an authentication bypass.
Can an attacker remotely exploit CVE-2026-62911?
Yes, CVE-2026-62911 can be exploited remotely by an authorized attacker to elevate their privileges.