CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0289 [1.01] [H/H] Vulnerabilities patched in Microsoft Exchange Server

unknownpublic exploitCVE-2026-62911
Microsoft has patched vulnerabilities in Exchange Server. An attacker can exploit the vulnerabilities to perform a Denial-of-Service, impersonate other users, grant themselves elevated privileges, execute arbitrary code, and/or gain access to sensitive data. Update: For the vulnerability identified as CVE-2026-62911, proof-of-concept code has been published. This vulnerability allows an unauthenticated attacker to execute arbitrary code. As a result, the attacker can gain access to mailboxes of Exchange users, and the vulnerability can be exploited to perform further attacks on the victim's network.

CSIRTS triage

What
Microsoft Exchange Server contains vulnerabilities allowing unauthenticated attackers to execute arbitrary code, deny service, impersonate users, escalate privileges, and access sensitive data; proof-of-concept code exists for CVE-2026-62911.
Who is affected
All Exchange Server deployments; CVE-2026-62911 affects unauthenticated remote attackers and can lead to mailbox access.
Urgency
Critical; proof-of-concept published for unauthenticated remote code execution vulnerability with immediate exploitation risk.
Action
Apply Microsoft security patches for CVE-2026-62911 and all related Exchange Server vulnerabilities immediately.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Exchange Server

Get an email when a new Exchange Server advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-08-28
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0289

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-62911coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Microsoft Exchange Server

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from NCSC-NL Advisories