CVE-2026-62911: Security Update for On-Premises Exchange Servers
This text was generated using artificial intelligence (AI).Microsoft released CVE-2026-62911 on August 11, 2026. The vulnerability affects locally operated Microsoft Exchange servers. Exchange Online is not affected.
Heise Online reports that 85 percent On-premises Exchange servers in Germany are vulnerable to CVE-2026-62911. For companies with locally operated Exchange environments, it is therefore important to take stock of publicly accessible email services and the available update path.
SE RTM SU9 (KB5121573, released August 11, 2026), Exchange 2016 CU23 via ESU Period 2 (for ESU subscribers only), Exchange 2019 via ESU Period 2 (for ESU participants only)
Vulnerability: CVE-2026-62911 (CVSS 8.0, high)
Status: No active abuse has been documented
Authentication Bypass via Capture-Replay
According to the Microsoft Security Response Center, CVE-2026-62911 is a privilege escalation vulnerability caused by an authentication bypass via capture-replay. The vulnerability was discovered by Orange Tsai of the DEVCORE Research Team and coordinated through the Trend Micro Zero Day Initiative.
CVE-2026-62911 is not a standalone, unauthenticated remote code execution vulnerability. However, according to the Microsoft Security Response Center, when chained with other vulnerabilities, it can escalate to unauthenticated code execution before login.
One relevant service is the MRSProxy endpoint of the MailboxReplicationProxyService. If Extended Protection is missing, the endpoint can serve as a relay destination for NTLM relay using the PetitPotam technique. Possible consequences include the compromise of mailboxes with read, send, and attachment download capabilities.
A public proof-of-concept exploit is available on GitHub (hypnguyen1209/CVE-2026-62911). As of this publication, there are no confirmed reports of active exploitation in the wild.
Affected Exchange versions
The vulnerability affects the following on-premises products:
Microsoft Exchange Server 2016 CU23
Microsoft Exchange Server 2019
Microsoft Exchange Server SE RTM
According to Microsoft, Exchange Online is not affected. This distinction is relevant for hybrid Exchange environments in which on-premises servers are operated alongside cloud-based email services.
Security Update and Technical Measures
Microsoft Support provides Exchange Server SE RTM the security update SU9 (KB5121573) Ready. For Exchange 2016 CU23 and Exchange 2019 is an update on Extended Security Updates Period 2 is scheduled, provided that the ESU is participating. This period runs from May through October 2026.
The following measures are planned for locally operated Exchange servers:
Apply the security update for Exchange Server SE RTM.
For Exchange 2016 CU23 and Exchange 2019, check ESU enrollment and the available update path.
Restrict access from the Internet to trusted source IP addresses or route it through a VPN.
Disable MRSProxy unless the service is needed.
Plan to switch to Exchange Server SE or migrate to Exchange Online or alternative solutions.
For operators of locally hosted Exchange servers in Germany and Austria, this vulnerability also has regulatory implications. If attackers gain access to mailbox contents containing personal data, a reporting obligation under Article 33 of the GDPR may arise—affected data controllers must then report the incident to the competent data protection supervisory authority within 72 hours. For organizations subject to NIS 2 in Germany and Austria, additional sector-specific reporting obligations apply. The BSI has published a cybersecurity alert regarding CVE-2026-62911.
List Exchange services accessible from outside the organization
Locally operated Exchange servers may be publicly accessible under customer domains, for example, via mail servers, OWA fingerprints, or Autodiscover endpoints. These services can be included in an external inventory of an organization.
LocateRisk identifies publicly accessible systems and the software being used. This can help identify external Exchange instances and prioritize them for patch status checks. However, detecting an external service does not necessarily indicate which specific version of the software is vulnerable.
For service providers, C-VRM can provide alerts when critical vulnerabilities exist or when the security level changes. This allows organizations to classify their own external Exchange services and publicly accessible systems separately from those of suppliers.
Am I affected?
This affects Microsoft Exchange Server in the versions listed above; the vulnerability has been fixed in. If you want to know whether Microsoft Exchange Server is even visible in your own externally accessible infrastructure, you can use the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed from the outside—the key factor is comparing it with the manufacturer's advisory.
The following on-premises versions are affected: Microsoft Exchange Server 2016 CU23, Microsoft Exchange Server 2019, and Microsoft Exchange Server SE RTM. Exchange Online is not affected.
Microsoft is releasing security update SU9 (KB5121573) for Exchange Server SE RTM. Exchange Server 2016 CU23 and Exchange Server 2019 receive updates through Extended Security Updates Program Period 2, which runs from May through October 2026 and requires ESU enrollment.
As of the time of publication, there is no confirmed active exploitation in the wild. However, a public proof-of-concept exploit is available on GitHub, which increases the urgency of applying the patch.
As of August 31, 2026. This article is intended for general informational purposes only and does not constitute legal, security, or operational advice in specific cases. The security situation and patch availability may have changed since publication; the linked manufacturer advisory is always authoritative. Despite careful research, we do not guarantee that the information is up-to-date, accurate, or complete.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2024-3094
Passive Assessment
Information About the CVENotes found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.