Critical RCE Vulnerability in Microsoft Exchange Server Disclosed

Critical RCE Vulnerability in Microsoft Exchange Server Disclosed

First seen 1 Sep 2026, 06:59 UTC SocprimeGbhackers 71.2

Article Content

Browse articles
ThreatCluster

A critical pre-authentication remote code execution vulnerability, CVE-2026-62911, affects Microsoft Exchange Server due to inadequate enforcement of Extended Protection on the MRSProxy HTTP.sys endpoint. Attackers can exploit this flaw via an NTLM relay, gaining machine account privileges and potentially achieving SYSTEM-level control. The vulnerability was demonstrated at Pwn2Own Berlin 2026 and has a public proof-of-concept available. Organizations using affected versions of Exchange should apply Microsoft security updates KB5121576, KB5121575, KB5121574, or KB5121573. Exchange 2016, which reached end-of-life in October 2025, requires Extended Security Updates for continued protection. Security teams are advised to monitor for unauthorized file creation and unusual WCF service activity. The situation is urgent as the PoC code is publicly available, increasing the risk of exploitation.

Key Points: • CVE-2026-62911 allows pre-auth RCE on Microsoft Exchange Server. • Public PoC code released following demonstration at Pwn2Own Berlin 2026. • Organizations must apply Microsoft security updates to mitigate risks.

Timeline

2026-08-11
CVE-2026-62911 published
Microsoft disclosed a critical pre-authentication RCE vulnerability affecting Exchange Server.
Socprime
2026-08-22
First public PoC released
A public proof-of-concept for CVE-2026-62911 was made available, demonstrating the exploit.
Gbhackers
2026-08-31
Vulnerability demonstration at Pwn2Own
Orange Tsai showcased the exploit chain involving CVE-2026-62911 at Pwn2Own Berlin 2026.
Socprime
2026-09-01
Security advisory issued
Organizations are urged to apply security updates and monitor for suspicious activity related to the vulnerability.
Gbhackers