THREATOPS
THREAT OPSThreat News › Microsoft Exchange Vulnerability CVE-2026-62911: What Administrators Should Do and How Zscaler Can Help

Microsoft Exchange Vulnerability CVE-2026-62911: What Administrators Should Do and How Zscaler Can Help

medzscaler_threatlabzPublished 2026-09-03

Microsoft's August 2026 Patch Tuesday included a fix for CVE-2026-62911, a high-severity authentication bypass vulnerability affecting Exchange Server 2016, 2019, and Subscription Edition. The severity has a CVSS score of 8.0 from Microsoft. As of September 1, threat intelligence group Shadowserver has identified around 22,000 Exchange servers that remain unpatched and exposed to the int

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.zscaler.com/blogs/product-insights/microsoft-exchange-vulnerability-cve-2026-62911-what-administrators-should