CTIPilot

Microsoft Exchange Server

product · product:microsoft-exchange-server

Also known as: Exchange Server

Coverage timeline
2
first 2026-05-18 → last 2026-08-29
Peak priority
critical
1 critical · 1 high
Sources cited
12
9 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
6
see Co-occurring entities below
ATT&CK techniques
12
pinned v19.2 · see below

Hunting pivots

Releases covered
Microsoft Exchange Server 2016 ×2Microsoft Exchange Server 2019 ×2Microsoft Exchange Server Subscription Edition ×2

ATT&CK techniques

12 techniques observed across 2 entries, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-29/exchange-mrsproxy-auth-bypass-cve-2026-62911-poc · ATT&CK page ↗

T1566Phishing×1

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

Evidence: 2026-05-18/cve-2026-42897-exchange-owa-em-service-auto-mitigation-depen · ATT&CK page ↗

Execution TA0002

T1203Exploitation for Client Execution×1

Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility.

Evidence: 2026-05-18/cve-2026-42897-exchange-owa-em-service-auto-mitigation-depen · ATT&CK page ↗

Persistence TA0003

T1098.002Account Manipulation: Additional Email Delegate Permissions×1

Adversaries may grant additional permission levels to maintain persistent access to an adversary-controlled email account.

Evidence: 2026-05-18/cve-2026-42897-exchange-owa-em-service-auto-mitigation-depen · ATT&CK page ↗

Privilege Escalation TA0004

T1068Exploitation for Privilege Escalation×1

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-08-29/exchange-mrsproxy-auth-bypass-cve-2026-62911-poc · ATT&CK page ↗

T1098.002Account Manipulation: Additional Email Delegate Permissions×1

Adversaries may grant additional permission levels to maintain persistent access to an adversary-controlled email account.

Evidence: 2026-05-18/cve-2026-42897-exchange-owa-em-service-auto-mitigation-depen · ATT&CK page ↗

Stealth TA0005

T1027Obfuscated Files or Information×1

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Evidence: 2026-05-18/cve-2026-42897-exchange-owa-em-service-auto-mitigation-depen · ATT&CK page ↗

Credential Access TA0006

T1552Unsecured Credentials×1

Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).

Evidence: 2026-05-18/cve-2026-42897-exchange-owa-em-service-auto-mitigation-depen · ATT&CK page ↗

T1557Adversary-in-the-Middle×1

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

Evidence: 2026-08-29/exchange-mrsproxy-auth-bypass-cve-2026-62911-poc · ATT&CK page ↗

Collection TA0009

T1185Browser Session Hijacking×1

Adversaries may take advantage of security vulnerabilities and inherent functionality in browser software to change content, modify user-behaviors, and intercept information as part of various browser session hijacking techniques.

Evidence: 2026-05-18/cve-2026-42897-exchange-owa-em-service-auto-mitigation-depen · ATT&CK page ↗

T1557Adversary-in-the-Middle×1

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

Evidence: 2026-08-29/exchange-mrsproxy-auth-bypass-cve-2026-62911-poc · ATT&CK page ↗

Command and Control TA0011

T1071.001Application Layer Protocol: Web Protocols×1

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-05-18/cve-2026-42897-exchange-owa-em-service-auto-mitigation-depen · ATT&CK page ↗

T1071.004Application Layer Protocol: DNS×1

Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-05-18/cve-2026-42897-exchange-owa-em-service-auto-mitigation-depen · ATT&CK page ↗

T1102.001Web Service: Dead Drop Resolver×1

Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.

Evidence: 2026-05-18/cve-2026-42897-exchange-owa-em-service-auto-mitigation-depen · ATT&CK page ↗

Story timeline

  1. 2026-08-29CVE-2026-62911, Microsoft Exchange Server MRSProxy: a missing channel-binding check lets a relayed Negotiate authentication take over every mailbox, public exploit code now live sixteen days after the patch
    trending-vulnerabilitiesA working public exploit for an Exchange mailbox-move endpoint lands sixteen days after Patch Tuesday, and MSRC's exploitability rating has not moved
  2. 2026-05-18CVE-2026-42897 Exchange OWA, EM Service auto-mitigation depends on outbound connectivity to officemitigations.microsoft.com
    trending-vulnerabilities

Where this entity is cited

  • trending-vulnerabilities2

Source distribution

  • msrc.microsoft.com3 (25%)
  • techcommunity.microsoft.com2 (17%)
  • advisories.ncsc.nl1 (8%)
  • frankysweb.de1 (8%)
  • heise.de1 (8%)
  • proofpoint.com1 (8%)
  • security-hub.ncsc.admin.ch1 (8%)
  • social.bund.de1 (8%)
  • other1 (8%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (12)

Entries about Microsoft Exchange Server (2)

2026-08-29 · view entry permalink →

HIGHCVE-2026-62911updatedNATOB2

CVE-2026-62911, Microsoft Exchange Server MRSProxy: a missing channel-binding check lets a relayed Negotiate authentication take over every mailbox, public exploit code now live sixteen days after the patch

CVE-2026-62911 (CWE-294, Authentication Bypass by Capture-Replay) was patched in Microsoft's 11 August 2026 Exchange Server security release, at the time rated "Exploitation Less Likely" (Microsoft Security Response Center, 2026-08-11). NCSC-NL revised its own advisory (NCSC-2026-0289) on 2026-08-28 specifically to record the public proof-of-concept and raised its likelihood/damage assessment from medium/high to high/high as a result (NCSC-NL, 2026-08-28). The flaw sits in the MRSProxy endpoint Exchange exposes for cross-server mailbox moves: MRSProxy accepts Negotiate authentication but never validates channel bindings, the check Extended Protection for Authentication depends on (Franky's Web, 2026-08-27). Without that check, an attacker who captures or coerces a Negotiate/NTLM authentication exchange can relay it to MRSProxy and be treated as the relayed account rather than as themselves; Microsoft's own FAQ confirms the resulting access lets an attacker "take over the mailboxes of all Exchange users... send emails, read emails, download attachments" (Microsoft Security Response Center, 2026-08-11). The flaw was discovered by Orange Tsai of DEVCORE Research Team and demonstrated at Pwn2Own Berlin 2026 as one link in a three-vulnerability chain that together achieved SYSTEM-level remote code execution on Exchange, reported to Microsoft through the Zero Day Initiative (Franky's Web, 2026-08-27). Working exploit code was published on GitHub around 27 August 2026 (sixteen days after the patch) and MSRC's exploitability rating has not been revised since its 11 August publication despite the public proof-of-concept (Franky's Web, 2026-08-27). Affected are all Exchange Server builds below the August 2026 cumulative/security update across Exchange Server SE, 2019 (CU14 and CU15) and 2016 (CU23); there is no workaround via Exchange Emergency Mitigation, so the update must be installed directly, and updates for Exchange 2016 and 2019 are available only through Microsoft's paid Extended Security Updates (ESU) program; organizations without a current ESU license will not receive the patch (Franky's Web, 2026-08-27). No in-the-wild exploitation has been reported as of this writing.

MSRC's own CVSS vector scores the precondition as PR:L/UI:R, an "authorized attacker" with some user interaction (Microsoft Security Response Center, 2026-08-11), but Franky's Web's technical description, Germany's CERT-Bund and the Dutch NCSC-NL all independently characterise the flaw as exploitable by an attacker with no authentication at all. CERT-Bund states the public exploit "enabl[es] the complete remote takeover of systems without authentication" (CERT-Bund, 2026-08-28), and NCSC-NL's own advisory states plainly that the flaw "allows an unauthenticated attacker to execute arbitrary code" (NCSC-NL, 2026-08-28). A third-party technical reconstruction of the exploit chain narrows what "coerce or capture" requires in practice: MB VRED's own most plausible hypothesis (not a confirmed finding) is that the attacker needs an existing foothold on the internal, domain-joined network to issue an MS-EFSR (PetitPotam-style) coercion call against one Exchange server, capturing its machine-account authentication and relaying it to the MRSProxy endpoint on a different Exchange server ("The attacker sits inside the network, especially inside a domain-joined PC!") and the technique needs at least two Exchange servers in the environment, since "the captured hash cannot be relayed to itself." MB VRED frames this as requiring "lot of non-realistic conditions to be exploited in the real world", specifically, outbound connectivity from an Exchange server and inbound access on ports domain users do not normally reach it on, closing with "So, for the defensive guys, don’t be panic!" (MB VRED, 2026-08-13). Weighing two independent national CERTs' plain "unauthenticated" characterization against both the vendor's own CVSS labelling and this single, uncorroborated hypothesis about the network position it may actually require, any Exchange server below the August 2026 build should still be patched on the CERTs' own stated urgency, but MB VRED's own caveats are a reason for caution before assuming this is exploitable from the open internet without any existing foothold on the target's network. Detection concept: authentication and session telemetry for MRSProxy/EWS access running under the Exchange server's own machine-account context but originating from unexpected source hosts, a legitimate mailbox move originates internally, not via relayed external traffic, with Windows Security Event 4624 Logon Type 3 network logons in that account context as the platform-specific anchor.

Working exploit code has surfaced for the critical Exchange vulnerability CVE-2026-62911 from the August update.

This endpoint accepts Negotiate authentication but does not check the so-called channel bindings. It is precisely this check that enforces Extended Protection.

Franky's Web 2026-08-27

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

What privileges could be gained by an attacker who successfully exploited the vulnerability? The attacker would be able to take over the mailboxes of all Exchange users, attackers can send emails, read emails, download attachments.

Microsoft Security Response Center 2026-08-11

A PoC exploit has been published for the critical vulnerability CVE-2026-62911 in Microsoft Exchange, enabling the complete remote takeover of systems without authentication. (translated from German)

CERT-Bund (BSI) 2026-08-28

This vulnerability allows an unauthenticated attacker to execute arbitrary code. (translated from Dutch)

NCSC-NL

Currently, however, around 85% of on-premises Exchange servers in Germany are still vulnerable to this vulnerability. (translated from German)

CERT-Bund (BSI) 2026-08-28

Currently, however, we are only aware of 9 Exchange servers 2016/2019 in Germany on which patches issued under ESU are installed. (translated from German)

BSI, via heise Security

The attacker sits inside the network, especially inside a domain-joined PC!

This one works only for multiple Exchange servers setup because the captured hash cannot be relayed to itself!

It requires lot of non-realistic conditions to be exploited in the real world:

So, for the defensive guys, don’t be panic!

MB VRED 2026-08-13
Updaterun 2026-09-01T0411Z-intelsourcesevidenceactionscvessourcing_notebody

Following a press inquiry, Germany's CERT-Bund (part of the BSI) disclosed on 2026-08-28 that most of the country's on-premises Exchange population had still not applied the August patch: "Currently, however, around 85% of on-premises Exchange servers in Germany are still vulnerable to this vulnerability" (translated from German) (CERT-Bund, 2026-08-28). BSI states it has been proactively notifying German network operators about still-vulnerable systems in their networks since 2026-08-14 (heise Security, 2026-08-31). For the small population of Exchange 2016/2019 installs still supported only through the paid Extended Security Updates program, BSI says it is aware of only nine servers in Germany with the ESU patch installed (BSI, via heise Security, 2026-08-31). BSI's standing advice is unchanged: restrict internet-facing access to an Exchange server's web-based services to trusted source IP ranges, or place it behind a VPN.

This is the operationally important delta for any DACH-region on-prem Exchange operator, including Swiss cantonal and communal administrations running Exchange on-premises: German telemetry indicates that most operators in a comparable environment have not applied a two-week-old patch against a pre-auth, mailbox-wide takeover chain with public exploit code. "We applied the August patch" should be verified against the actual installed build number, not assumed from a routine patch-cycle checklist.

vulnerability29 Aug 04:09Zmulti-sourceOpen finding ↗

2026-05-18 · view entry permalink →

CRITICALCVE-2026-42897exploitedupdatedNATOA1

CVE-2026-42897 Exchange OWA, EM Service auto-mitigation depends on outbound connectivity to officemitigations.microsoft.com

UPDATE (originally covered 2026-05-15 / deep-dive 2026-05-16): The Microsoft Exchange Team Blog post addressing CVE-2026-42897 was last modified 2026-05-17 to clarify an operational dependency that defenders must verify on every Exchange Mailbox host: the Exchange Emergency Mitigation Service (EM Service / EEMS) (which auto-applies the URL-Rewrite mitigation labelled M2.1.x) only delivers that mitigation when it can reach officemitigations.microsoft.com over outbound HTTPS. Segmented on-premises Exchange 2016 / 2019 / Subscription-Edition deployments that block direct outbound HTTPS from the Mailbox role will therefore not have received the automatic mitigation and remain exposed to the actively-exploited OWA stored-XSS chain.

The CVE remains CISA KEV-listed (added 2026-05-15) with no permanent cumulative-update fix as of 2026-05-18; Microsoft states verbatim "We are working on developing and testing a more permanent fix which we will provide when it meets our quality standards." Exchange Online is unaffected. Operational verification per server: Get-ExchangeDiagnosticInfo -Server <server> -Process EdgeTransport -Component EmergencyMitigation returns Status: Active and rule M2.1.x applied; manual application on hosts that cannot reach the mitigation service: .\EOMT.ps1 -CVE "CVE-2026-42897" from an elevated Exchange Management Shell, or apply the documented URL Rewrite rule by hand.

The Exchange Emergency Mitigation Service will provide mitigation automatically, and is on by default. If it is not already enabled on your Exchange Server, you need to enable Exchange Emergency Mitigation Service.

We are working on developing and testing a more permanent fix which we will provide when it meets our quality standards.

Microsoft Exchange Team Blog 2026-07-14

The messages exploit CVE-2026-42897, a vulnerability in Outlook Web Access in which the server does not adequately sanitize HTML in the message body. This allows a loader piece of JavaScript to use the onload= event handler to parse the rest of the message body, assemble a Base64 fragment, and execute it as encoded JavaScript.

This persistent access lives on the server-side and requires deliberate removal from the Exchange server; credential rotation and even full re-imaging of the targeted user's device will not evict the actor.

Proofpoint 2026-07-29

Installing the July 2026 update does not automatically remove already applied CVE-2026-42897 mitigations.

Microsoft Exchange Team Blog 2026-07-14
Updaterun 2026-07-31T0409Z-intelactionsaffected_productscvesentitiesevidencereferencesregionssectorssourcestagstechniquesbody

The May entry tracked CVE-2026-42897 as an Exchange OWA flaw whose interim protection depended on the EM Service auto-mitigation. Two things changed. Proofpoint has now attributed in-the-wild exploitation to a named Russian state-supported actor and published the implant's full mechanics (Proofpoint, 2026-07-29), and the mitigation is no longer the remediation; the July 2026 Security Update is, with the mitigation now something that must be actively torn down (Microsoft Exchange Team Blog, 2026-07-14). NCSC-CH appended the Proofpoint reporting to its own advisory on 2026-07-30 (NCSC Switzerland, 2026-07-30).

The actor is TA488, which Microsoft tracks as Void Blizzard and which this pipeline registers as LAUNDRY BEAR, the same Russian state-supported email-espionage actor a 16-nation joint advisory exposed on 2026-07-23 for its Zimbra campaign. Proofpoint assesses OWAReaper as an evolution of that campaign's ZimReaper payload, citing shared code including an identical invisible-element sizing and error-handling pattern (Proofpoint, 2026-07-29). Campaign activity began 2026-07-22 against government, telecommunications, finance, hospitality and aerospace targets across the US and Europe, using deliberately banal lure subjects with no call to action, Proofpoint reads the unusual breadth as intentional blending with bulk mail. Its stated infrastructure-creation date of March 2026 precedes Microsoft's May disclosure by two months, which is the basis for its assessment that zero-day use is feasible; that is an inference from infrastructure dating, not a confirmed finding.

Execution. The flaw is a failure to sanitise HTML in the message body, so a loader script in an onload= handler reassembles a Base64 fragment from the rest of the message and evaluates it, no link click and no attachment open, only viewing the message in OWA. The exploit and payload fragments are hidden inside the message's social-media icon elements, with next-stage data placed after # fragment markers where the browser's Base64 image parser stops reading, so the payload is not visible to casual inspection of the HTML. On execution OWAReaper first rewrites the delivered message server-side to strip the exploit content and suppresses OWA pop-ups and right-click, then enumerates the victim's address, username and settings.

Credential and token theft. It creates two invisible input elements and waits for the browser's own autofill to populate them with the saved OWA username and password. Separately it enumerates installed Outlook add-ins holding ReadWriteMailbox permission and, where one exists, abuses it to call GetClientAccessToken and obtain OAuth tokens.

Persistence, in three independent layers. Client-side, the implant writes an AES-encrypted copy of itself and a decryption wrapper into browser localStorage under a settings field of the legitimate PageDataPayload.OwaUserDefaultSettings key, which OWA itself evaluates during its own sync-restore flow, so every ordinary OWA tab-open re-launches it with no separate loader. A second client-side layer adds a hidden iframe to messages cached in OWA's offline IndexedDB store, so opening the cached message re-infects an endpoint even after a full re-image. The third is server-side and is the one that matters most: the implant calls UpdateFolder to grant Owner-level permission on every mail folder to the low-privilege "Default" preset alias that exists in every Exchange organisation. Proofpoint is explicit that this "requires deliberate removal from the Exchange server" and that credential rotation and re-imaging will not evict it.

Command and control. Two channels, both over infrastructure defenders generally trust. The implant polls GitHub's public Commit Search API every 24 hours for crafted commit messages containing the target's own email address, decrypting matches to a four-character command header that selects toolkit replacement, C2-domain rotation, or one-off code execution; in parallel it re-parses cached inbound messages every five minutes for the same command structure. Exfiltration runs primarily over HTTPS with encrypted URI paths, either relayed through a set of legitimate image-CDN domains or sent directly to the actor-controlled server when those proxies fail; if the HTTPS method fails altogether, the implant switches to DNS label tunnelling, packing the data into the subdomain labels of ordinary DNS queries for an actor-controlled domain. Notably, Proofpoint states there is no mass mailbox exfiltration here, unlike the Zimbra campaign, which is why this entry maps browser-session and credential-access behaviour rather than bulk email collection.

Patching. The permanent fix is the July 2026 Security Update, available as Exchange SE RTM publicly and for Exchange 2019 CU14/CU15 and Exchange 2016 CU23 only through the Period 2 Extended Security Update programme; organisations that were enrolled only in Period 1, which ended in April 2026, do not receive it (Microsoft Exchange Team Blog, 2026-07-14). Microsoft's own vulnerability record scores the flaw 8.1 and marks it exploited (Microsoft Security Response Center, 2026-07-14). Installing the update does not remove a previously applied mitigation: administrators who used the EM Service must remove the M2.1.0 IIS rules through the documented rollback, and those who ran the downloadable mitigation script must run its rollback. The known operational side effects of the mitigation era (broken OWA calendar printing, inline-image rendering problems, OWA-light failing, and false-unhealthy calendar-proxy health alerts) only clear once both steps are done, so a server left on mitigation-only status keeps them indefinitely (Microsoft Exchange Team Blog, 2026-05-14).

Detection. The highest-value signal is in mailbox audit and Exchange Web Services telemetry: a folder-permission change granting Owner rights to the "Default" alias, applied across many folders of one mailbox in quick succession. Client-side, monitor for writes to the OWA user-default-settings localStorage key outside the browser's own sync flow, and for OWA sessions in which invisible form inputs are created and immediately populated. On the network side, two egress patterns stand out from a mail client's normal behaviour: repeated polling of a public source-code hosting search API on a roughly daily cadence, and DNS queries with the label-length and entropy profile of tunnelled data.

Triage: OWA legitimately reads and writes its own settings keys constantly, so the presence of localStorage activity is not the signal; the discriminator is the specific settings-field path carrying an encrypted blob, and its correlation with a message open. For the server-side artifact the discrimination is cleaner: administrators do grant folder permissions, but they grant them to named users or groups for a specific folder, not Owner rights to the built-in "Default" alias across an entire mailbox. Treat any such grant as compromise until proven otherwise.

Improvementrun 2026-08-30T1312Z-auditactionsclassification

This entry now carries a source-reliability rating, which it predates: A1 on the NATO Admiralty scale. The letter reflects Microsoft's own advisory for its own product, the number reflects independent corroboration, since Proofpoint analysed the implant separately from Microsoft's disclosure and NCSC-CH restated that analysis for its own constituency. Nothing in the assessment or the remediation guidance changes; the rating makes explicit what the sourcing already supported.

Builds on: 2026-07-24/laundry-bear-zimbra-zero-click-cve-2025-66376

vulnerability18 May 05:00Zmulti-sourceOpen finding ↗