Forwarded from Taiwan Computer Emergency Response Coordination Center Cybersecurity Information Alert NISAC-200-202609-00000007
[Content Description]
Researchers discovered that Microsoft Exchange Server contains an Authentication Bypass vulnerability(CVE-2026-62911). Authenticated remote attackers can induce users to interact with specially crafted content to intercept and replay authentication credentials, thereby bypassing the server's authentication mechanism, escalating privileges, and gaining access to users' mailboxes on the server. Please confirm and patch as soon as possible.
[Affected Platforms]
Microsoft Exchange Server 2016 Cumulative Update 23 15.01.2507.072(exclusive) and earlier versions
[Recommended Measures]
The official source has released patches for the vulnerability. Please update to the following versions Microsoft Exchange Server 2016 Cumulative Update 23 15.01.2507.072(inclusive) or later versions Microsoft Exchange Server 2019 Cumulative Update 14 15.02.1544.044(inclusive) or later versions Microsoft Exchange Server 2019 Cumulative Update 15 15.02.1748.049(inclusive) or later versions Microsoft Exchange Server Subscription Edition RTM 15.02.2562.046(inclusive) or later versions
For detailed information, please refer to the official advisory at the following URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62911
[References]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-62911
2. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62911