PoC released for critical Exchange Server RCE vulnerability (CVE-2026-62911)
cyb3rops · x · 2026-08-26
A proof-of-concept (PoC) has been released for Microsoft Exchange Server vulnerability CVE-2026-62911, a pre-authentication remote code execution (RCE) flaw requiring no credentials. The exploit leverages a lack of Extended Protection on an HTTP.sys endpoint to relay machine account hashes, gaining privileges. It then abuses a file write parameter to drop an ASPX webshell, resulting in full SYSTEM takeover.
More from Safety
- Moonshot in talks with Microsoft, Amazon, Google over K3 revenue sharing — pstAsiatech · 2026-08-26
- UK AI Safety Institute faces scrutiny over rogue AI incident and 'safety washing' — aiamblichus · 2026-08-26
- Inside OpenAI's Reboot: A Deep Dive by TIME — timemagazine · 2026-08-26
- WIRED: AI slop ruins cute animals online as deepfakes erode trust — nordicinst · 2026-08-26
- Taiwan indicts nine over Nvidia chip smuggling, including manager who cleared banned B300 GPUs — SimplyAnnisa · 2026-08-26
- RL's a Hell of a Drug: Metagaming, Reward Seeking & Motivated CoT Reasoning — The Cognitive Revolution · 2026-08-26