Skip to content
Auto-CTI
Back to all deep dives
ZERO DAY INITIATIVE - BLOG

The August 2026 Security Update Review

KEV MEDIUM CVE-2026-62911 Exchange Server Pwn2Own privilege escalation
The August 2026 Security Update Review

Strategic summary

Exchange Server Elevation of Privilege (CVE-2026-62911) enables authentication bypass and takeover of all mailboxes; demonstrated as proof-of-concept at Pwn2Own Berlin.

Relevance for you

Exchange Server Elevation of Privilege (CVE-2026-62911) enables authentication bypass and takeover of all mailboxes; demonstrated as proof-of-concept at Pwn2Own Berlin.

Mentioned CVEs

Risk score

61
cvss base
70.00
kev bonus
20.00
epss bonus
0.00
poc bonus
15.00
raw before weight
105.00
industry weight
1.21
freshness factor
0.50
exploitability factor
1.00
days old
28.00
vendor mismatch penalty
0.00
consensus penalty
-3.00

Path: operational

Consensus check

The pipeline self-checks before delivery. These rules lowered the score:

  • TTP_SKIPPED TTP mapping skipped (placeholder or aggregation article) −3
Consensus penalty:
−3.0
Total penalty:
−3.0
ESC