Security & Threat Intelligence · 12.08.2026, 02:25 UTC
ZDI-26-538: (Pwn2Own) Microsoft Exchange Improper Authorization Privilege Escalation Vulnerability
| Schweregrad | high |
|---|---|
| CVSS | 8.8 |
| CVE | ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | Zero Day Initiative ↗ |
| Veröffentlicht | 12.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad hoch (CVSS 8.8). Betroffene Kennungen: CVE-2026-62911. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
This vulnerability allows remote attackers to escalate privileges on affected installations of Microsoft Exchange. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-62911.
Maßnahmen
⬇ Als MarkdownVerwandte Beiträge
- info Best GPU Neoclouds 2026: CoreWeave, Nebius, Lambda, Crusoe, and Groq Ranked by Published Pricing and Contracted Power
- info Anthropic brings Mythos 5 to its Claude Security vulnerability scanner
- info How agents can delegate better
- info Why API Test Generation Is a Judgment Problem, Not a Code Generation Problem