ID:13035 - Exploit for Authentication Bypass by Capture-replay in Microsoft Exchange Server - CVE-2026-62911

 
Main Vulnerability Database Exploits ID:13035 - Exploit for Authentication Bypass by Capture-replay in Microsoft Exchange Server - CVE-2026-62911

ID:13035 - Exploit for Authentication Bypass by Capture-replay in Microsoft Exchange Server - CVE-2026-62911

Published: September 2, 2026


Vulnerability identifier: #VU141972
Vulnerability risk: Medium
CVE-ID: CVE-2026-62911
CWE-ID: CWE-294
Exploitation vector: Remote access
Vulnerable software:
Microsoft Exchange Server

Link to public exploit:


Vulnerability description

The vulnerability allows a remote user to elevate privileges.

The vulnerability exists due to the server is susceptible to authentication bypass by capture-replay. A remote authenticated user can take over the mailboxes of all Exchange users.


Remediation

Install updates from vendor's website.