CVE Tools
Back to feed
PoC public Microsoft Exchange Server auth-bypass Microsoft zero-day

Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)

Help Net Security·By Sinisa Markovic··2 min read
CVE Tools coverage

A working exploit for CVE-2026-62911 has appeared online, leaving nearly 22,000 instances of Microsoft Exchange Server vulnerable to a critical authentication bypass. This flaw allows attackers to elevate privileges over the network, with the United States and Germany reporting the highest concentration of unpatched systems. Microsoft issued a fix on August 11, 2026, following disclosure by Orange Tsai in collaboration with Trend Micro’s Zero Day Initiative.