ALITEQ.

hackers showed microsoft exactly how to read every inbox on your exchange server live, at a hacking contest

CVE-2026-62911 only scores an 8.0, but it came with working exploit code demonstrated at Pwn2Own Berlin — and it doesn't stop at one mailbox.

Priya NairUpdated 1d ago7 min readWeb story
Person checking an email inbox on a laptop in an office

Security researchers didn't just find a bug in Exchange Server this year — they demonstrated it live, in front of an audience, and handed Microsoft the working exploit code afterward. CVE-2026-62911 lets an attacker who can capture and replay an authentication token take over every mailbox on the server: read it, send from it, download every attachment sitting in it. Microsoft patched it on August 11. If you're running Exchange 2016, 2019, or the newer Subscription Edition on-premises, this is not a 'get to it eventually' patch.

What 'authentication bypass by capture-replay' actually means

Skip the jargon and it's this: instead of stealing a password, an attacker captures a legitimate authentication token in transit and replays it to convince the server it's talking to a validated user. Microsoft's security update guide lists it as an elevation-of-privilege bug over a network, and its 8.0 score puts it well inside Critical — but 8.0 doesn't have the shock value of a 9.8 or a perfect 10, which is exactly why this one is easy to under-prioritize on a busy patch list.

8.0

CVSS score

Critical severity

Pwn2Own Berlin

Where it was shown

Live, working exploit

Aug 11, 2026

Patch released

Same day across four builds

All of them

Mailboxes at risk

Server-wide, not per-account

The part that should worry unpatched shops more than the CVSS number

ZDI's August 2026 review makes a point worth repeating: Microsoft's own exploitability index initially leaned toward 'exploitation less likely,' and the researchers explicitly say to disregard that given what they watched happen at the contest. A working proof-of-concept demonstrated in front of a room full of security researchers is a completely different threat model than a bug that exists only in a vendor's internal risk model.

Server room with network cables and rack-mounted equipment
The flaw lets an attacker read, send, and download attachments from every mailbox on an affected Exchange server — not just the account they compromised first. · Unsplash

Who's actually exposed, and who's stuck

The August 11 cumulative updates cover Exchange Server 2019 CU14 and CU15, Exchange Server Subscription Edition RTM, and Exchange Server 2016 CU23. But both Exchange 2016 and 2019 are already past their mainstream support dates, and Microsoft is only shipping this fix to organizations enrolled in Extended Security Updates, Period 2 — coverage that itself runs out at the end of October 2026. If you're on an unsupported build with no ESU contract, there's no patch coming for you at all. That's not a hypothetical edge case; it describes a lot of small and mid-size organizations running on-prem Exchange because migrating off it has never made it to the top of the budget list.

1

Identify every on-prem Exchange server in your environment — 2016, 2019, and Subscription Edition all need this fix.

Confirm your ESU enrollment status if you're on 2016 or 2019 — without it, no patch is coming for you.

3

Apply KB5121573 (SE RTM), KB5121574 (2019 CU15), KB5121575 (2019 CU14), or KB5121576 (2016 CU23) as appropriate to your build.

4

After patching, review mailbox audit logs for anomalous read or send activity predating the fix.

Why this fits a pattern from the last few weeks

This is the third time this cycle a piece of on-prem Microsoft server software has taken a serious public hit — see the SharePoint exploit chain and the wormable Windows DNS Server flaw from earlier this month, plus the ongoing fight over Defender's own patch bypass. Add in the pre-Patch-Tuesday CVSS 10 bugs in Azure and Teams, and August 2026 is shaping up to be one of the roughest single months for on-prem Microsoft infrastructure in a while. I don't think that's coincidence so much as attention — once researchers start finding this class of bug in one product, they go looking for it in the neighbors.

9/ 10

Verdict

Patch priority

Treat CVE-2026-62911 as same-day, not same-sprint. A public proof-of-concept from Pwn2Own combined with mailbox-wide exposure outranks its 8.0 score on paper.

Best for: Any organization running on-premises Exchange Server 2016, 2019, or Subscription Edition

Does this affect Exchange Online / Microsoft 365?
No — this is an on-premises Exchange Server vulnerability. Exchange Online customers aren't affected by this specific CVE.
What if I'm on Exchange 2016 or 2019 without an ESU contract?
Then Microsoft isn't shipping you this patch at all — both versions are past mainstream support, and only Extended Security Updates Period 2 customers are covered, through the end of October 2026. Migrating off unsupported Exchange is the actual fix here, not a workaround.
Is exploit code public?
The working exploit was demonstrated live at Pwn2Own Berlin and handed to Microsoft under responsible disclosure — it wasn't published openly. Once a technique has been proven in front of a room of researchers, treat independent replication as a matter of time, not possibility.
Do I need to worry if my mailboxes only hold internal, non-sensitive email?
Yes — server-wide mailbox access means an attacker can pivot from any compromised account into every other one, including whichever mailbox actually does hold something worth stealing.

Pwn2Own exists to break things in public so vendors fix them before criminals do — it worked exactly as intended here. Whether it actually protects your mailboxes now depends entirely on whether you're one of the organizations Microsoft is still shipping patches to.

Software & Systems Editor

Priya Nair

Priya has daily-driven more Linux distros than she can name and treats her setup like a workshop. She covers the operating systems, apps and settings worth your time — and cheerfully calls out the 'optimizations' that just quietly break your machine.

Work out the hardware

The Aliteq brief

The tech worth knowing — hardware, AI, gaming, deals. No spam, unsubscribe anytime.

Keep reading