Microsoft Exchange Server vulnerability CVE-2026-62911

A high-severity vulnerability has been identified in Microsoft Exchange Server (CVE-2026-62911). The vulnerability is caused by an authentication bypass flaw that allows reuse of previously intercepted authentication data (capture-replay attack). Successful exploitation can enable an attacker with initially limited access rights to escalate privileges within the network and compromise the confidentiality, integrity, and availability of Exchange Server data. It is recommended to install the appropriate Microsoft security update as soon as possible and ensure that Exchange Server is updated to at least the following version: CERT.LV advises evaluating the necessity of exposing Exchange servers to the external internet. Outdated Exchange servers that no longer receive security updates should be isolated from the external internet and gradually upgraded to supported Exchange Server versions. Additional information: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62911

This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.

Read original source