⚠️ PATCH NOW
Microsoft Exchange has an auth-bypass flaw (CVE-2026-62911) that relays a server's own account into a webshell running as SYSTEM.
A public exploit just dropped, and 21,899 servers are still exposed.
Patch, then turn on Extended Protection.
https://suriq.io/blog/exchange-cve-2026-62911-auth-bypass-webshell-poc














