Description:
Forwarding Taiwan Computer Emergency Response Team / Coordination Center Cybersecurity Alert NISAC-200-202609-00000007
Researchers have discovered an Authentication Bypass vulnerability (CVE-2026-62911) in Microsoft Exchange Server. An authenticated remote attacker could trick a user into interacting with specially crafted content to intercept and replay authentication credentials, thereby bypassing the server's authentication mechanism, elevating privileges, and gaining access to user mailboxes on the server. Please confirm and perform patching as soon as possible.
Affected Platforms:
Recommended Actions:
References:
-
-
Computer and Communication Center
Network System Division