← nejvýznamnější zprávy · všechny zprávy

SPOJENO PŘES CVE EPSS 0.01

Závažná zranitelnost ohrožuje téměř 22 000 Microsoft Exchange serverů

Microsoft 11. srpna 2026 vydal opravu zranitelnosti CVE-2026-62911 (CVSS 8,0), přesto téměř 22 000 veřejně dostupných Exchange serverů zůstává zranitelných. V Česku Shadowserver eviduje přibližně 300 unikátních IP adres Exchange serverů, které vyhodnocuje jako zranitelné (na jednu či více zranitelností). Zranitelnost postihuje Exchange Server 2016, 2019 a Subscription Edition a může vést až k převzetí uživatelských e-mailových schránek. Exploit je již veřejně dostupný. Verze 2016 a 2019 jsou…

Číst originál na CSIRT.CZ (CZ.NIC) →

6 zpráv z 4 zdrojů · první 11. 8. 07:00 · poslední 2. 9. 13:53 CZ · EN/orig

Microsoft finance veřejná správa CZ NL US

tg: zneužíváno tg: zranitelnost tp: identita

CVE v události 1

CVEhodnoceníKEVEPSS
CVE-2026-62911 8.0 3.1 · microsoft 0.01

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 8.8.

Jak se o tom psalo 6

  1. · CSIRT.CZ (CZ.NIC) CZ nadpis události

    Závažná zranitelnost ohrožuje téměř 22 000 Microsoft Exchange serverů

    Microsoft 11. srpna 2026 vydal opravu zranitelnosti CVE-2026-62911 (CVSS 8,0), přesto téměř 22 000 veřejně dostupných Exchange serverů zůstává zranitelných. V Česku Shadowserver eviduje přibližně 300 unikátních IP adres Exchange serverů, které vyhodnocuje jako zranitelné (na jednu či více zranitelností). Zranitelnost postihuje Exchange Server 2016, 2019 a Subscription Edition a může vést až k převzetí uživatelských e-mailových schránek. Exploit je již veřejně dostupný. Verze 2016 a 2019 jsou…

  2. · NCSC-NL NL

    NCSC-2026-0289 [1.01] [H/H] Kwetsbaarheden verholpen in Microsoft Exchange server

    Microsoft heeft kwetsbaarheden verholpen in Exchange Server. Een kwaadwillende kan de kwetsbaarheden misbruiken om een Denial-of-Service uit te voeren, zich voor te doen als andere gebruiker, zich verhoogde rechten toe te kennen, willekeurige code uit te voeren en/of toegang te krijgen tot gevoelige gegevens. **Update**: Voor de kwetsbaarheid met kenmerk CVE-2026-62911 is proof-of-concept-code gepubliceerd. Deze kwetsbaarheid stelt een ongeauthenticeerde kwaadwillende in staat om willekeurige…

  3. · Microsoft Security US

    CVE-2026-62911 Microsoft Exchange Server Elevation of Privilege Vulnerability

    Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

  4. · Zero Day Initiative US

    ZDI-26-534: (Pwn2Own) Microsoft Exchange Capture-Replay Authentication Bypass Vulnerability

    This vulnerability allows remote attackers to bypass authentication on affected installations of Microsoft Exchange. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-62911.

  5. · Zero Day Initiative US

    ZDI-26-535: (Pwn2Own) Microsoft Exchange External Control of File Path Remote Code Execution Vulnerability

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Exchange. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-62911.

  6. · Zero Day Initiative US

    ZDI-26-538: (Pwn2Own) Microsoft Exchange Improper Authorization Privilege Escalation Vulnerability

    This vulnerability allows remote attackers to escalate privileges on affected installations of Microsoft Exchange. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-62911.