Posting Date: 2026/09/10

【Vulnerability Alert】High-Risk Security Vulnerability in Microsoft Exchange Server (CVE-2026-62911), Please Confirm and Patch Promptly

  • Subject: 【Vulnerability Alert】High-Risk Security Vulnerability in Microsoft Exchange Server (CVE-2026-62911), Please Confirm and Patch Promptly


  • Description:
    • Forwarding Taiwan Computer Emergency Response Team / Coordination Center Cybersecurity Alert NISAC-200-202609-00000007
    • Researchers have discovered an Authentication Bypass vulnerability (CVE-2026-62911) in Microsoft Exchange Server. An authenticated remote attacker could trick a user into interacting with specially crafted content to intercept and replay authentication credentials, thereby bypassing the server's authentication mechanism, elevating privileges, and gaining access to user mailboxes on the server. Please confirm and perform patching as soon as possible.
  • Affected Platforms:
    • Microsoft Exchange Server 2016 Cumulative Update 23 prior to version 15.01.2507.072 (exclusive)
  • Recommended Actions:
    • Official patches for the vulnerability have been released. Please update to the following versions or later: Microsoft Exchange Server 2016 Cumulative Update 23 version 15.01.2507.072 (inclusive) or later; Microsoft Exchange Server 2019 Cumulative Update 14 version 15.02.1544.044 (inclusive) or later; Microsoft Exchange Server 2019 Cumulative Update 15 version 15.02.1748.049 (inclusive) or later; Microsoft Exchange Server Subscription Edition RTM version 15.02.2562.046 (inclusive) or later.
    • For detailed information, please refer to the official advisory at: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62911
  • References:

Computer and Communication Center
Network System Division