PoC released for critical Exchange Server RCE vulnerability (CVE-2026-62911)

cyb3rops · x · 2026-08-26

A proof-of-concept (PoC) has been released for Microsoft Exchange Server vulnerability CVE-2026-62911, a pre-authentication remote code execution (RCE) flaw requiring no credentials. The exploit leverages a lack of Extended Protection on an HTTP.sys endpoint to relay machine account hashes, gaining privileges. It then abuses a file write parameter to drop an ASPX webshell, resulting in full SYSTEM takeover.

Original post →

More from Safety

Safety channel →