ZDI-26-538: (Pwn2Own) Microsoft Exchange Improper Authorization Privilege Escalation Vulnerability
ZDI discloses a Pwn2Own Microsoft Exchange privilege-escalation flaw (CVE-2026-62911, CVSS 8.8) where the required authentication can be bypassed.
ZDI advisory ZDI-26-538 describes CVE-2026-62911, an improper authorization vulnerability in Microsoft Exchange rated CVSS 8.8. Remote attackers can escalate privileges, and while authentication is nominally required, the existing authentication mechanism can be bypassed. The vulnerability was demonstrated at Pwn2Own.