ZDI-26-534: (Pwn2Own) Microsoft Exchange Capture-Replay Authentication Bypass Vulnerability
Pwn2Own-demoed CVE-2026-62911 capture-replay authentication bypass in Microsoft Exchange allows unauthenticated remote attacks, CVSS 8.1.
ZDI-26-534 describes a capture-replay authentication bypass vulnerability in Microsoft Exchange, demonstrated at Pwn2Own, allowing remote attackers to bypass authentication without credentials. ZDI assigned a CVSS score of 8.1, and the flaw is tracked as CVE-2026-62911. Exchange servers are widely deployed enterprise mail infrastructure.