Vulnerability threat dossier

CVE-2026-62911

microsoftexchange server

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

VTP deterministic threat16.6of 100 · CVSS excluded

VTP analyst assessment

Microsoft Exchange capture-replay privilege elevation

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence80%
Public exploitation · VTP factREPORTED

Assessment

Microsoft Exchange Server has an authentication-bypass-by-capture-replay flaw requiring an authorized attacker and user interaction. BleepingComputer reported nearly 22,000 exposed unpatched Exchange servers and mailbox-hijack risk. Apply the available update and reduce unnecessary internet exposure.

Why it matters

  • Successful exploitation could give an attacker elevated access to Exchange data and mailboxes.
  • If you use affected Exchange Server versions, apply Microsoft's update and restrict external access to essential services.

Evidence

2 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The general Patch Tuesday exploitation assertion maps to reporting about a different Windows vulnerability.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Unexpected mailbox access or changes following suspicious authentication activity.

AI baseline history (5)
  1. BASELINE ASSESSED
    Microsoft Exchange capture-replay privilege elevationgpt-5.6-terra · low
  2. BASELINE ASSESSED
    Microsoft Exchange Server capture-replay bypassgpt-5.6-terra · low
  3. BASELINE ASSESSED
    Microsoft Exchange capture-replay authentication bypassgpt-5.6-sol · high
  4. BASELINE ASSESSED
    Microsoft Exchange capture-replay authentication bypassgpt-5.6-sol · high
  5. BASELINE ASSESSED
    Exchange capture-replay privilege escalationgpt-5.6-sol · high
Technical severityHIGHCVSS 8.0 · technical context
Public exploitationREPORTEDGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.0151th percentile · prediction
Evidence confidence60%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    EPSS is 0.01; this is predictive context, not exploitation evidence.

  2. 02

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

CERT ADVISORYNew CERT advisory
RESEARCH PUBLICATIONNew technical research
03

Claim provenance

Evidence and source independence

6publications detected
6underlying evidence chains

2 primary sources · 0 dependent secondary reports · 4 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:6e9bdfac90455c6fff0468b9b1c36d280a95f9d076dea96986c72a6686c7b74bACTIVE
Evidence
04

Event history

Threat timeline

  1. 00:0012 Aug
    CERT ADVISORY

    New CERT advisory

    CERT-FR published evidence linked to CVE-2026-62911.

  2. 22:2111 Aug
    RESEARCH PUBLICATION

    New technical research

    Cisco Talos published evidence linked to CVE-2026-62911.

  3. 18:4611 Aug
    EXPLOITATION REPORTED

    Exploitation Reported

    SecurityWeek supplied a deterministically extracted signal; review the linked evidence before escalation.

05

Original publications

Source record

In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation

Noteworthy stories that might have slipped under the radar: Microsoft rolled out patches for cloud services, hackers compromised 5,000 Dropbox accounts, and Guardio is now valued at $1.1 billion. The post In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation appeared first on SecurityWeek .

CVE-2026-62911
Separate evidence group
Original

Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. [...]

CVE-2026-42897CVE-2026-62911
Separate evidence group
Original

Multiples vulnérabilités dans les produits Microsoft (12 août 2026)

De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

CVE-2026-40375CVE-2026-47285CVE-2026-54123CVE-2026-54981CVE-2026-57105CVE-2026-58612CVE-2026-58639CVE-2026-58650CVE-2026-59113CVE-2026-59119CVE-2026-62827CVE-2026-62829CVE-2026-62837CVE-2026-62839CVE-2026-62871CVE-2026-62886CVE-2026-62897CVE-2026-62898CVE-2026-62899CVE-2026-62900CVE-2026-62901CVE-2026-62902CVE-2026-62909CVE-2026-62910CVE-2026-62911CVE-2026-62912CVE-2026-62913CVE-2026-62914CVE-2026-62915CVE-2026-62917CVE-2026-63512CVE-2026-63514CVE-2026-63516CVE-2026-63520CVE-2026-64897CVE-2026-64900CVE-2026-64901CVE-2026-64902CVE-2026-64916CVE-2026-64921CVE-2026-64922CVE-2026-65658CVE-2026-65660CVE-2026-65663CVE-2026-65665CVE-2026-65673CVE-2026-65675CVE-2026-65680CVE-2026-65767CVE-2026-65768CVE-2026-65769CVE-2026-65811CVE-2026-65813CVE-2026-65815CVE-2026-66301CVE-2026-66805CVE-2026-66808CVE-2026-68821CVE-2026-69278CVE-2026-69306CVE-2026-69320CVE-2026-70306CVE-2026-70321CVE-2026-70324CVE-2026-70326CVE-2026-70335CVE-2026-70336CVE-2026-70337CVE-2026-70338CVE-2026-70354CVE-2026-70355
Separate evidence group
Original

Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical."

CVE-2026-49163CVE-2026-50481CVE-2026-50515CVE-2026-50516CVE-2026-56161CVE-2026-56162CVE-2026-58650CVE-2026-59115CVE-2026-59118CVE-2026-59124CVE-2026-59132CVE-2026-59133CVE-2026-61348CVE-2026-61358CVE-2026-61925CVE-2026-61929CVE-2026-61930CVE-2026-62688CVE-2026-62696CVE-2026-62698CVE-2026-62712CVE-2026-62713CVE-2026-62721CVE-2026-62735CVE-2026-62737CVE-2026-62741CVE-2026-62766CVE-2026-62783CVE-2026-62788CVE-2026-62815CVE-2026-62816CVE-2026-62817CVE-2026-62818CVE-2026-62819CVE-2026-62820CVE-2026-62822CVE-2026-62823CVE-2026-62824CVE-2026-62827CVE-2026-62830CVE-2026-62832CVE-2026-62836CVE-2026-62869CVE-2026-62873CVE-2026-62878CVE-2026-62888CVE-2026-62889CVE-2026-62890CVE-2026-62893CVE-2026-62896CVE-2026-62911CVE-2026-62918CVE-2026-63508CVE-2026-63513CVE-2026-63515CVE-2026-63518CVE-2026-63519CVE-2026-63520CVE-2026-63522CVE-2026-63525CVE-2026-63526CVE-2026-63532CVE-2026-64898CVE-2026-64903CVE-2026-64907CVE-2026-64909CVE-2026-64910CVE-2026-64911CVE-2026-64921CVE-2026-65657CVE-2026-65664CVE-2026-65665CVE-2026-65667CVE-2026-65668CVE-2026-65775CVE-2026-65788CVE-2026-65789CVE-2026-65791CVE-2026-66799CVE-2026-66802CVE-2026-66804CVE-2026-66807CVE-2026-68794CVE-2026-68804CVE-2026-68816CVE-2026-68820CVE-2026-68823CVE-2026-69278CVE-2026-70130CVE-2026-70307CVE-2026-70332CVE-2026-70335CVE-2026-70355CVE-2026-71331
Separate evidence group
Original

August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

A use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges. The post August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day appeared first on SecurityWeek .

CVE-2024-38193CVE-2025-21418CVE-2025-32709CVE-2026-59124CVE-2026-62815CVE-2026-62832CVE-2026-62878CVE-2026-62893CVE-2026-62911CVE-2026-6726CVE-2026-6727CVE-2026-68820CVE-2026-72971
Separate evidence group
Original

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Today is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities. [...]

CVE-2026-18577CVE-2026-40375CVE-2026-42976CVE-2026-47285CVE-2026-47299CVE-2026-49163CVE-2026-49179CVE-2026-50472CVE-2026-50481CVE-2026-50515CVE-2026-50516CVE-2026-54113CVE-2026-54123CVE-2026-54981CVE-2026-54984CVE-2026-56161CVE-2026-56162CVE-2026-56174CVE-2026-56179CVE-2026-57104CVE-2026-57105CVE-2026-58612CVE-2026-58639CVE-2026-58641CVE-2026-58650CVE-2026-58651CVE-2026-59113CVE-2026-59115CVE-2026-59118CVE-2026-59119CVE-2026-59122CVE-2026-59124CVE-2026-59125CVE-2026-59126CVE-2026-59127CVE-2026-59128CVE-2026-59130CVE-2026-59131CVE-2026-59132CVE-2026-59133CVE-2026-59134CVE-2026-59135CVE-2026-59136CVE-2026-59137CVE-2026-59138CVE-2026-61345CVE-2026-61346CVE-2026-61347CVE-2026-61348CVE-2026-61349CVE-2026-61350CVE-2026-61352CVE-2026-61353CVE-2026-61355CVE-2026-61356CVE-2026-61357CVE-2026-61358CVE-2026-61359CVE-2026-61360CVE-2026-61361CVE-2026-61363CVE-2026-61364CVE-2026-61365CVE-2026-61366CVE-2026-61367CVE-2026-61368CVE-2026-61918CVE-2026-61920CVE-2026-61921CVE-2026-61923CVE-2026-61924CVE-2026-61925CVE-2026-61926CVE-2026-61927CVE-2026-61928CVE-2026-61929CVE-2026-61930CVE-2026-61932CVE-2026-61933CVE-2026-61934CVE-2026-61936CVE-2026-61937CVE-2026-61938CVE-2026-61939CVE-2026-62688CVE-2026-62690CVE-2026-62692CVE-2026-62693CVE-2026-62695CVE-2026-62696CVE-2026-62698CVE-2026-62699CVE-2026-62700CVE-2026-62701CVE-2026-62702CVE-2026-62703CVE-2026-62705CVE-2026-62707CVE-2026-62708CVE-2026-62709CVE-2026-62710CVE-2026-62711CVE-2026-62712CVE-2026-62713CVE-2026-62714CVE-2026-62715CVE-2026-62716CVE-2026-62717CVE-2026-62718CVE-2026-62719CVE-2026-62720CVE-2026-62721CVE-2026-62722CVE-2026-62723CVE-2026-62724CVE-2026-62725CVE-2026-62726CVE-2026-62728CVE-2026-62729CVE-2026-62730CVE-2026-62732CVE-2026-62733CVE-2026-62734CVE-2026-62735CVE-2026-62736CVE-2026-62737CVE-2026-62738CVE-2026-62739CVE-2026-62740CVE-2026-62741CVE-2026-62742CVE-2026-62743CVE-2026-62745CVE-2026-62746CVE-2026-62747CVE-2026-62748CVE-2026-62749CVE-2026-62750CVE-2026-62751CVE-2026-62752CVE-2026-62753CVE-2026-62754CVE-2026-62755CVE-2026-62757CVE-2026-62758CVE-2026-62761CVE-2026-62766CVE-2026-62768CVE-2026-62769CVE-2026-62770CVE-2026-62771CVE-2026-62772CVE-2026-62773CVE-2026-62774CVE-2026-62775CVE-2026-62776CVE-2026-62777CVE-2026-62778CVE-2026-62779CVE-2026-62780CVE-2026-62781CVE-2026-62782CVE-2026-62783CVE-2026-62784CVE-2026-62785CVE-2026-62786CVE-2026-62787CVE-2026-62788CVE-2026-62790CVE-2026-62792CVE-2026-62793CVE-2026-62795CVE-2026-62796CVE-2026-62797CVE-2026-62798CVE-2026-62799CVE-2026-62800CVE-2026-62803CVE-2026-62807CVE-2026-62811CVE-2026-62812CVE-2026-62814CVE-2026-62815CVE-2026-62816CVE-2026-62817CVE-2026-62818CVE-2026-62819CVE-2026-62820CVE-2026-62822CVE-2026-62823CVE-2026-62824CVE-2026-62827CVE-2026-62829CVE-2026-62830CVE-2026-62832CVE-2026-62836CVE-2026-62837CVE-2026-62839CVE-2026-62842CVE-2026-62869CVE-2026-62871CVE-2026-62872CVE-2026-62873CVE-2026-62876CVE-2026-62877CVE-2026-62878CVE-2026-62880CVE-2026-62881CVE-2026-62882CVE-2026-62883CVE-2026-62885CVE-2026-62886CVE-2026-62887CVE-2026-62888CVE-2026-62889CVE-2026-62890CVE-2026-62892CVE-2026-62893CVE-2026-62894CVE-2026-62896CVE-2026-62897CVE-2026-62898CVE-2026-62899CVE-2026-62900CVE-2026-62901CVE-2026-62902CVE-2026-62908CVE-2026-62909CVE-2026-62910CVE-2026-62911CVE-2026-62912CVE-2026-62913CVE-2026-62914CVE-2026-62915CVE-2026-62917CVE-2026-62918CVE-2026-63508CVE-2026-63512CVE-2026-63513CVE-2026-63514CVE-2026-63515CVE-2026-63516CVE-2026-63517CVE-2026-63518CVE-2026-63519CVE-2026-63520CVE-2026-63521CVE-2026-63522CVE-2026-63524CVE-2026-63525CVE-2026-63526CVE-2026-63527CVE-2026-63528CVE-2026-63529CVE-2026-63530CVE-2026-63531CVE-2026-63532CVE-2026-63533CVE-2026-64897CVE-2026-64898CVE-2026-64899CVE-2026-64900CVE-2026-64901CVE-2026-64902CVE-2026-64903CVE-2026-64904CVE-2026-64905CVE-2026-64906CVE-2026-64907CVE-2026-64908CVE-2026-64909CVE-2026-64910CVE-2026-64911CVE-2026-64912CVE-2026-64914CVE-2026-64915CVE-2026-64916CVE-2026-64917CVE-2026-64919CVE-2026-64920CVE-2026-64921CVE-2026-64922CVE-2026-65656CVE-2026-65657CVE-2026-65658CVE-2026-65660CVE-2026-65661CVE-2026-65662CVE-2026-65663CVE-2026-65664CVE-2026-65665CVE-2026-65667CVE-2026-65668CVE-2026-65671CVE-2026-65672CVE-2026-65673CVE-2026-65675CVE-2026-65678CVE-2026-65679CVE-2026-65680CVE-2026-65681CVE-2026-65767CVE-2026-65768CVE-2026-65769CVE-2026-65773CVE-2026-65774CVE-2026-65775CVE-2026-65776CVE-2026-65777CVE-2026-65778CVE-2026-65779CVE-2026-65780CVE-2026-65781CVE-2026-65782CVE-2026-65783CVE-2026-65784CVE-2026-65785CVE-2026-65786CVE-2026-65787CVE-2026-65788CVE-2026-65789CVE-2026-65790CVE-2026-65791CVE-2026-65794CVE-2026-65795CVE-2026-65796CVE-2026-65797CVE-2026-65798CVE-2026-65799CVE-2026-65806CVE-2026-65807CVE-2026-65810CVE-2026-65811CVE-2026-65813CVE-2026-65814CVE-2026-65815CVE-2026-66301CVE-2026-66799CVE-2026-66802CVE-2026-66804CVE-2026-66805CVE-2026-66806CVE-2026-66807CVE-2026-66808CVE-2026-66809CVE-2026-66810CVE-2026-6726CVE-2026-6727CVE-2026-68792CVE-2026-68793CVE-2026-68794CVE-2026-68795CVE-2026-68796CVE-2026-68797CVE-2026-68798CVE-2026-68799CVE-2026-68800CVE-2026-68801CVE-2026-68802CVE-2026-68803CVE-2026-68804CVE-2026-68805CVE-2026-68806CVE-2026-68807CVE-2026-68808CVE-2026-68809CVE-2026-68810CVE-2026-68811CVE-2026-68812CVE-2026-68813CVE-2026-68814CVE-2026-68815CVE-2026-68816CVE-2026-68817CVE-2026-68819CVE-2026-68820CVE-2026-68821CVE-2026-68823CVE-2026-69278CVE-2026-69306CVE-2026-69320CVE-2026-70130CVE-2026-70304CVE-2026-70306CVE-2026-70307CVE-2026-70310CVE-2026-70311CVE-2026-70312CVE-2026-70313CVE-2026-70314CVE-2026-70315CVE-2026-70316CVE-2026-70317CVE-2026-70318CVE-2026-70319CVE-2026-70320CVE-2026-70321CVE-2026-70322CVE-2026-70323CVE-2026-70324CVE-2026-70325CVE-2026-70326CVE-2026-70327CVE-2026-70328CVE-2026-70329CVE-2026-70330CVE-2026-70332CVE-2026-70335CVE-2026-70336CVE-2026-70337CVE-2026-70338CVE-2026-70340CVE-2026-70344CVE-2026-70345CVE-2026-70346CVE-2026-70347CVE-2026-70348CVE-2026-70354CVE-2026-70355CVE-2026-71331CVE-2026-72971
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score16.6vtp-threat-v1-public
Public exploitation12 / 30
EPSS prediction0.14 / 20
Exploit availability2.5 / 15
Source independence0 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CWE
CWE-294
CPE records
38
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.