Microsoft has patched multiple vulnerabilities in Exchange Server that could allow attackers to perform Denial-of-Service attacks, impersonate users, escalate privileges, execute arbitrary code, and access sensitive data. A notable update highlights that proof-of-concept code has been published for CVE-2026-62911, which allows unauthenticated remote code execution. Exploitation of this vulnerability could grant attackers access to Exchange user mailboxes. The flaw could also be leveraged to launch further attacks against the victim's network. The availability of public PoC code significantly raises the risk of active exploitation in the wild.
Multiple vulnerabilities have been identified and patched in Microsoft Exchange Server. These vulnerabilities can be exploited by a malicious actor to perform Denial-of-Service attacks, impersonate other users, elevate privileges, execute arbitrary code, and/or gain access to sensitive data. Notably, CVE-2026-62911 has a published proof-of-concept exploit. This specific vulnerability allows an unauthenticated attacker to execute arbitrary code, potentially gaining access to Exchange user mailboxes and enabling further attacks on the victim's network. Exchange Server 2016 and 2019 have reached end-of-life and only receive security updates through Microsoft's Extended Security Update (ESU) program.
1. Install the security updates provided by Microsoft as soon as possible. Refer to https://portal.msrc.microsoft.com/en-us/security-guidance for update details, installation instructions, and any available workarounds. 2. For Exchange Server 2016 and 2019 (end-of-life): enroll in Microsoft's ESU program to continue receiving security updates, or restrict these servers to be accessible only from internal networks. 3. Plan to phase out unsupported Exchange Server versions (2016/2019) that do not receive ESU support. 4. Prioritize patching CVE-2026-62911 due to the availability of public proof-of-concept exploit code and the risk of unauthenticated remote code execution.