Microsoft Exchange Server 2016/2019/SE authentication bypass (CVE-2026-62911)
Vulnerability
Summary
Hide ▲
Show ▼
An authentication bypass in Microsoft Exchange Server 2016/2019/SE leaves about 21,899 exposed servers at risk of mailbox takeover. The flaw is tracked as CVE-2026-62911, and Microsoft patched it in the August 2026 Patch Tuesday. Exploit code is already reported online, increasing urgency for operators that have not yet installed the update.
Related Happenings
Microsoft Windows passkey relay mitigation for CVE-2026-34348
Advisory/Mitigation
H score31
First: 10.08.2026 15:25
Last: 10.08.2026 15:25
Sources 1
About this happening:
Microsoft's CVE-2026-34348 mitigation for Windows Event Logging Service and the reported passkey relay assertions issue reduces exposure to replay-style authentication...
Microsoft Windows passkey relay mitigation for CVE-2026-34348
Advisory/MitigationAbout this happening: Microsoft's CVE-2026-34348 mitigation for Windows Event Logging Service and the reported passkey relay assertions issue reduces exposure to replay-style authentication...
CCB urgent patch warning for CVE-2026-41089 on Windows servers
Public Sector Action
H score48
First: 01.06.2026 15:30
Last: 01.06.2026 15:30
Sources 1
About this happening:
Belgium's CCB warned that CVE-2026-41089 is being actively exploited in the wild, urging admins to immediately patch vulnerable Windows servers because the fla...
CCB urgent patch warning for CVE-2026-41089 on Windows servers
Public Sector ActionAbout this happening: Belgium's CCB warned that CVE-2026-41089 is being actively exploited in the wild, urging admins to immediately patch vulnerable Windows servers because the fla...
Microsoft Exchange CVE-2026-42897 mitigation advisory
Advisory/Mitigation
H score44
First: 15.05.2026 12:40
Last: 15.05.2026 12:40
Sources 1
About this happening:
CVE-2026-42897 is an Exchange Outlook Web Access (OWA) cross-site scripting flaw that Microsoft says was being exploited as a zero-day against Outlook on the web u...
Microsoft Exchange CVE-2026-42897 mitigation advisory
Advisory/MitigationAbout this happening: CVE-2026-42897 is an Exchange Outlook Web Access (OWA) cross-site scripting flaw that Microsoft says was being exploited as a zero-day against Outlook on the web u...
Latest development: 15.05.2026 15:35
Microsoft issued temporary mitigation guidance for CVE-2026-42897 while a patch is still in development, recommending the Exchange Emergency Mitigation (EM) Service, which is enabled by default and can be checked with the Exchange Health Checker script, or the Exchange On-premises Mitigation Tool (EOMT) for disconnected or air-gapped environments. Microsoft noted that the mitigations can disrupt features such as OWA Print Calendar and Inline images, and that servers older than March 2023 cannot receive new mitigations through EM Service.
Warlock ransomware post-exploitation tooling upgrades
Malware Activity
H score38
First: 17.03.2026 17:36
Last: 17.03.2026 17:36
Sources 1
About this happening:
The Warlock ransomware group has upgraded its post-exploitation toolset with BYOVD, TightVNC, and Yuze, making intrusions harder to detect and interrupt. In an obs...
Warlock ransomware post-exploitation tooling upgrades
Malware ActivityAbout this happening: The Warlock ransomware group has upgraded its post-exploitation toolset with BYOVD, TightVNC, and Yuze, making intrusions harder to detect and interrupt. In an obs...
Timeline
-
01.09.2026 15:38 2 articles · 2h ago
Microsoft Exchange Server 2016/2019/SE authentication bypass (CVE-2026-62911)
Initial DisclosureCVE-2026-62911 emerged as a high-severity Exchange authentication bypass after Microsoft patched it in August 2026. Early evidence points to online exploit code and a large exposed population, but no confirmed in-the-wild abuse yet.
Show sources
- Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks — www.bleepingcomputer.com — 01.09.2026 15:38
- Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks — www.bleepingcomputer.com — 01.09.2026 15:38