ZDI-26-538: (Pwn2Own) Microsoft Exchange Improper Authorization Privilege Escalation Vulnerability
Published Aug 11, 2026
·Updated
This vulnerability allows remote attackers to escalate privileges on affected installations of Microsoft Exchange. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-62911.
Affected Software
1 affected component
Microsoft Exchange
Event History
Aug 11, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-26-538?
The severity of ZDI-26-538 is rated at 8.8 on the CVSS scale.
2
How do I fix ZDI-26-538?
To fix ZDI-26-538, apply the latest security patches provided by Microsoft for affected versions of Exchange.
3
What type of vulnerability is ZDI-26-538?
ZDI-26-538 is categorized as an improper authorization privilege escalation vulnerability.
4
Can ZDI-26-538 be exploited without authentication?
Exploitation of ZDI-26-538 requires authentication, but the authentication mechanism can be bypassed.
5
Which software is affected by ZDI-26-538?
ZDI-26-538 affects Microsoft Exchange installations.