:::

【資安漏洞預警】Microsoft Exchange Server存在高風險安全漏洞(CVE-2026-62911),請儘速確認並進行修補
【Security Vulnerability Alert】Microsoft Exchange Server Contains a High-Risk Security Vulnerability(CVE-2026-62911), Please Confirm and Patch as Soon as Possible

公告類別:行政公告
發佈日期:2026/09/18 至 2027/03/18
點閱數:64

轉發 台灣電腦網路危機處理暨協調中心 資安訊息警訊 NISAC-200-202609-00000007

[內容說明]
研究人員發現Microsoft Exchange Server存在身分鑑別繞過(Authentication Bypass)漏洞(CVE-2026-62911),已通過身分鑑別之遠端攻擊者可誘使使用者操作特製內容,用以攔截並重送身分鑑別憑證,藉此繞過伺服器之身分鑑別機制,進而提升權限並取得伺服器上使用者信箱之存取權,請儘速確認並進行修補。

[影響平台]
Microsoft Exchange Server 2016 Cumulative Update 23 15.01.2507.072(不含)以前版本

[建議措施]
官方已針對漏洞釋出修補程式,請更新至下列版本 Microsoft Exchange Server 2016 Cumulative Update 23 15.01.2507.072(含)以後版本 Microsoft Exchange Server 2019 Cumulative Update 14 15.02.1544.044(含)以後版本 Microsoft Exchange Server 2019 Cumulative Update 15 15.02.1748.049(含)以後版本 Microsoft Exchange Server Subscription Edition RTM 15.02.2562.046(含)以後版本

詳細說明請參考官方公告,網址如下: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62911

[參考資料]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-62911
2. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62911
Forwarded from Taiwan Computer Emergency Response Coordination Center Cybersecurity Information Alert NISAC-200-202609-00000007

[Content Description]
Researchers discovered that Microsoft Exchange Server contains an Authentication Bypass vulnerability(CVE-2026-62911). Authenticated remote attackers can induce users to interact with specially crafted content to intercept and replay authentication credentials, thereby bypassing the server's authentication mechanism, escalating privileges, and gaining access to users' mailboxes on the server. Please confirm and patch as soon as possible.

[Affected Platforms]
Microsoft Exchange Server 2016 Cumulative Update 23 15.01.2507.072(exclusive) and earlier versions

[Recommended Measures]
The official source has released patches for the vulnerability. Please update to the following versions Microsoft Exchange Server 2016 Cumulative Update 23 15.01.2507.072(inclusive) or later versions Microsoft Exchange Server 2019 Cumulative Update 14 15.02.1544.044(inclusive) or later versions Microsoft Exchange Server 2019 Cumulative Update 15 15.02.1748.049(inclusive) or later versions Microsoft Exchange Server Subscription Edition RTM 15.02.2562.046(inclusive) or later versions

For detailed information, please refer to the official advisory at the following URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62911

[References]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-62911
2. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62911

相關附件

※為降低附件原始檔案遭搜尋引擎索引之風險,公告附件將由瀏覽器先下載至本機暫存後再開啟。請確認使用環境安全後,再決定是否開啟附件。

返回列表