CVE-2026-62911
8
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Summary
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | 15.01.0.0 < 15.01.2507.072 | affected |
| Microsoft | Microsoft Exchange Server 2019 Cumulative Update 14 | 15.02.0.0 < 15.02.1544.044 | affected |
| Microsoft | Microsoft Exchange Server 2019 Cumulative Update 15 | 15.02.0.0 < 15.02.1748.049 | affected |
| Microsoft | Microsoft Exchange Server Subscription Edition RTM | 15.02.0.0 < 15.02.2562.046 | affected |
Weaknesses
- CWE-294: CWE-294: Authentication Bypass by Capture-replay
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: no
- Technical Impact: total
Additional References
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.