On the August Patchday, Microsoft also provided security fixes for Exchange Server. Now, the reporter of the vulnerability has published proof-of-concept code (PoC) demonstrating the exploitation of one of the highly critical security vulnerabilities. Cybercriminals are likely to adapt it quickly and add it to their attack toolkits.

Hiep Van Nguyen presents the PoC on GitHub, which Orange Tasi (Devcore) used at the Pwn2Own event in Berlin as part of a chain of three vulnerabilities to completely take over Exchange systems. Microsoft describes the security vulnerability as privilege escalation and, contrary to the CVSS classification, rates it as “critical” (CVE-2026-62911, CVSS 8.0, risk “high”). The leak is a potential replay attack that allows authorized attackers to escalate their privileges over the network and bypass authentication. Nguyen summarizes it more directly: the vulnerability allows the injection and execution of malicious code without prior authentication.

Affected Exchange Versions

Nguyen also discusses deeper details of the vulnerability for those interested. Microsoft has closed it in versions Exchange 2016 CU23 15.1.2507.72, 2019 CU14 15.2.1544.43, 2019 CU15 15.2.1748.48, and Exchange SE RTM 15.2.2562.45 and newer. Exchange 2016 reached its regular end-of-life in October 2025; security patches for it are only available as part of the Extended Security Update (ESU) program. Those who do not pay for it are left with a vulnerable system.