Microsoft has released security updates for multiple Exchange Server vulnerabilities that could allow denial-of-service, privilege escalation, remote code execution, spoofing, and security feature bypass attacks.
The flaws were disclosed on August 11, 2026, as part of Microsoft’s monthly Patch Tuesday release. Exchange Server Subscription Edition, Exchange Server 2019, and Exchange Server 2016 are among the supported products receiving security updates.
The most serious issue is CVE-2026-62911, a critical elevation-of-privileges vulnerability with a CVSS score of 8.0. The flaw is linked to CWE-294, known as authentication bypass by capture-replay.
An attacker with low privileges could exploit the issue over a network if they can convince a user to interact with a malicious request or resource.
Successful exploitation could allow the attacker to gain higher permissions within the Exchange environment. Security researchers have highlighted CVE-2026-62911 as a major concern because it was demonstrated at Pwn2Own Berlin.
Microsoft Exchange Server Vulnerabilities
Reports state that exploitation may enable an attacker to bypass authentication protections and access Exchange mailboxes, including the ability to read messages, send emails, and download attachments.
Although Microsoft lists exploit code maturity as unproven, the public demonstration means defenders should treat the vulnerability as a high-priority patching issue.
Another elevation-of-privilege flaw, CVE-2026-62910, has a CVSS score of 7.2 and is caused by improper control of resource identifiers, also known as resource injection.
The vulnerability requires high privileges, but exploitation is network-based and does not require user interaction. A threat actor with authorized access could abuse crafted requests to gain additional permissions and expand control over Exchange services.
Affected Vulnerabilities and CVEs:
CVE IDVulnerability typeAttack requirementsSecurity impactCVE-2026-62910Elevation of PrivilegeNetwork attack, low complexity, high privileges required, no user interactionAn authorized attacker could elevate privileges, potentially gaining SYSTEM-level accessCVE-2026-62911Elevation of PrivilegeNetwork attack, low complexity, low privileges required, user interaction requiredAn attacker could bypass authentication controls and elevate privileges in Exchange ServerCVE-2026-62912Denial of ServiceNetwork attack, low complexity, low privileges required, no user interactionAn attacker could cause Exchange Server service disruption or unavailabilityCVE-2026-62913Remote Code ExecutionNetwork attack, low complexity, low privileges required, no user interactionAn attacker could execute code on a vulnerable Exchange Server, affecting confidentiality, integrity, and availabilityCVE-2026-62914SpoofingNetwork attack, low complexity, low privileges required, user interaction requiredAn attacker could use malicious web content to spoof trusted Exchange-related content or target usersCVE-2026-62915Security Feature BypassNetwork attack, low complexity, low privileges required, no user interactionAn attacker could bypass authorization checks and perform unauthorized actions affecting data integrity
Microsoft also fixed CVE-2026-62912, a denial-of-service vulnerability caused by deserialization of untrusted data. The flaw has a CVSS score of 6.5 and requires low privileges to exploit.
An attacker could exploit it remotely without user interaction to disrupt the availability of an Exchange Server. While it does not directly affect confidentiality or integrity, a successful attack could interrupt email delivery, administrative operations, and business communications.
CVE-2026-62913 is a remote code execution vulnerability with a CVSS score of 8.8. The issue involves a heap-based buffer overflow and can be exploited over a network by an attacker with low privileges.
No user interaction is required. If exploited successfully, the flaw could allow an attacker to run code on a vulnerable Exchange Server, potentially leading to mailbox theft, persistence, lateral movement, data theft, or ransomware deployment.
The update also addresses CVE-2026-62914, a cross-site scripting spoofing vulnerability, and CVE-2026-62915, a security feature bypass caused by missing authorization controls.
These issues could help attackers impersonate trusted content, target Exchange users, or make unauthorized changes in affected environments. Organizations should install Microsoft’s August 2026 Exchange Server security updates as soon as possible.
Administrators should also review privileged accounts, monitor Exchange logs for abnormal authentication activity, investigate unusual mailbox access, and restrict unnecessary remote administrative access.
Exchange Online customers are already protected from these server-side flaws. However, organizations operating on-premises Exchange Server or Exchange management tools should apply the relevant updates without delay.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
The post Microsoft Exchange Server Vulnerabilities Enable DoS, Privilege Escalation, and RCE Attacks appeared first on Cyber Security News.



