PoC public Microsoft Exchange Server auth-bypass Microsoft zero-day
Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)
CVE Tools coverage
A working exploit for CVE-2026-62911 has appeared online, leaving nearly 22,000 instances of Microsoft Exchange Server vulnerable to a critical authentication bypass. This flaw allows attackers to elevate privileges over the network, with the United States and Germany reporting the highest concentration of unpatched systems. Microsoft issued a fix on August 11, 2026, following disclosure by Orange Tsai in collaboration with Trend Micro’s Zero Day Initiative.