ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-534: (Pwn2Own) Microsoft Exchange Capture-Replay Authentication Bypass Vulnerability

AI summary · glm-5.3

Pwn2Own-demoed CVE-2026-62911 capture-replay authentication bypass in Microsoft Exchange allows unauthenticated remote attacks, CVSS 8.1.

ZDI-26-534 describes a capture-replay authentication bypass vulnerability in Microsoft Exchange, demonstrated at Pwn2Own, allowing remote attackers to bypass authentication without credentials. ZDI assigned a CVSS score of 8.1, and the flaw is tracked as CVE-2026-62911. Exchange servers are widely deployed enterprise mail infrastructure.

  • Capture-replay authentication bypass in Microsoft Exchange
  • Demonstrated at Pwn2Own, no authentication required
  • CVSS 8.1, tracked as CVE-2026-62911
  • Exchange is broadly deployed enterprise infrastructure

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-62911
Capture-Replay Authentication Bypass in Microsoft Exchange Server

Microsoft Exchange Server contains an authentication bypass flaw (CWE-294) in which captured authentication material can be replayed, allowing an authorized attacker to elevate privileges over a network. Per the CVSS vector, the attack is network-based with low complexity but requires the attacker to already hold low privileges and some user interaction, and success yields high impact on confidentiality, integrity, and availability. Affected products include on-premises Exchange Server and Exchange Server Subscription Edition, though specific vulnerable version ranges are not specified in the available data. Public scans indicate nearly 22,000 Exchange servers remain exposed to the flaw following the August 2026 Patch Tuesday fixes. No in-the-wild exploitation, public proof-of-concept, or KEV listing is known; the bug was demonstrated at Pwn2Own (ZDI-26-534) and carries an EPSS estimate of 1.3% probability of exploitation within 30 days.

Do: Apply the Exchange Server security updates released in Microsoft's August 2026 Patch Tuesday (refer to Microsoft's advisory for the exact fixed builds) on all on-premises servers, prioritizing internet-facing systems running OWA, EWS, or ActiveSync. Until patched, limit network exposure of Exchange endpoints to trusted networks and monitor authentication logs for replay-style anomalies; per the scan data, roughly 22,000 servers still need the update.

8.01%
  • microsoft exchange server
  • microsoft exchange server subscription edition
large≈22,000 internet-exposed Exchange servers
Full article

This vulnerability allows remote attackers to bypass authentication on affected installations of Microsoft Exchange. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-62911.

This source does not provide full text. Read it at zerodayinitiative.com.