Summary: Microsoft patched an Exchange Server privilege-escalation flaw on August Patch Tuesday. On August 27, a public PoC dropped, tied to a Pwn2Own-grade exploit chain capable of full, unauthenticated server takeover. If you run Exchange on-prem, patch now.

Timeline

  1. August Patch TuesdayMicrosoft ships a fix for CVE-2026-62911 as part of its regular Exchange Server updates.
  2. August 27, 2026 — Security researcher Hiep Van Nguyen publishes proof-of-concept exploit code on GitHub. The bug was originally demonstrated by Orange Tsai (Devcore) at Pwn2Own Berlin, where it was one link in a three-vulnerability chain used to fully take over Exchange systems.

Reading our article? Try our product:

Full Protection for Windows Servers - Zero-Risk Trial

The vulnerability

  • CVE: CVE-2026-62911
  • CVSS: 8.0 (“high” by CVSS scoring)
  • Microsoft’s own rating: “Critical” — Microsoft overrides its own CVSS-derived severity here, which is unusual and a signal to take it seriously.
  • Official description: Privilege escalation via a replay attack, an already-authorized attacker can escalate privileges over the network and bypass authentication.
  • Researcher’s blunter summary: Nguyen describes the practical effect more directly, injection and execution of malicious code without prior authentication.
  • Why the gap between those two descriptions matters: This CVE was one link in the three-vulnerability Pwn2Own Devcore chain. Standalone, it’s an auth-bypass/privesc bug; chained, it’s part of a path to unauthenticated remote code execution. BSI’s own advisory describes the practical outcome as pre-auth takeover from the internet, consistent with Nguyen’s framing.

Patched in: Exchange 2016 CU23 (15.1.2507.72), Exchange 2019 CU14 (15.2.1544.43), Exchange 2019 CU15 (15.2.1748.48), Exchange SE RTM (15.2.2562.45) and newer. See: Microsoft Exchange Server Build Numbers, Cumulative Updates (CU), Security Updates (SU) and Release Dates

Patch / mitigation status

VersionStatus
Exchange SEPatch available: KB5121573
Exchange 2016 / 2019Regular support ended October 2025. Patches only available via the paid Extended Security Updates (ESU) program.

Mitigation advice (if you can’t patch immediately)

  • Restrict internet access to Exchange’s web-based services (e.g. OWA) to trusted source IP addresses.
  • Or put access behind a VPN.

What to do now

  • Apply KB5121573 (Exchange SE) or confirm ESU coverage and patch status (2016/2019).
  • Assume exploitation attempts are already happening or imminent — a working PoC tied to a Pwn2Own-grade exploit chain is close to a worst case for time-to-mass-exploitation. Early signs back that up: Germany’s CERT-Bund reported 85% of on-prem Exchange servers there still vulnerable as of late August, suggesting patch uptake is lagging broadly, not just in one region.
  • If you can’t patch right away, restrict external access to Exchange web services to trusted IPs, or require VPN.

Fortify Your Server with Messageware Security

Data breaches have increased by 72%, servers are compromised in under 90 minutes. Ensure you have multiple layers of security software protecting your Windows Servers.

Server Threat Guard (STG) for All Windows Servers: Next-gen server protection, providing detection, alerting, and response (MDR) to zero-day and server penetration cyber-attacks. No need to research complicated deployments and no learning curve to install and manage.

EPG Guard for Exchange Servers: Real-time security. Stop AD account lockouts, eliminate password attacks, intelligent GEO blocking, and prevent Exchange Server vulnerability probing.

Don’t leave your critical infrastructure vulnerable, be proactive and stay ahead of evolving threats.