vCDC Alert: Microsoft Exchange Server – important August 2026 security updates
- 2 days ago
- 2 min read
Management summary
Microsoft released an Exchange Server security update on 11 August 2026 addressing seven vulnerabilities. Organisations running Exchange on premises should deploy the update promptly and verify the server’s exposure and security posture. This is particularly important for legacy Exchange 2016/2019 environments outside normal support that require appropriate ESU entitlement for 2026 security updates.
What is the issue?
The August release addresses CVE-2026-62910 through CVE-2026-62915 as well as CVE-2026-65813. CVE-2026-62911 is a privilege-escalation issue involving capture-replay techniques for an already authenticated attacker. CVE-2026-62914 concerns spoofing/cross-site scripting related to OWA Light, which Microsoft disables permanently with the August update.
Why is this dangerous and what can an attacker do?
Exchange is business-critical and often closely connected to Active Directory, user identities, internal email, calendars and sensitive communications. Depending on the specific issue and existing access, an attacker may escalate privileges, replay authenticated sessions, manipulate web content, spoof information presented to users or access confidential communications. CVE-2026-62911 is not an unauthenticated internet RCE; existing authenticated access is required for that issue.
Recommended action
Install the current Microsoft Exchange security update for the supported Exchange Server Subscription Edition branch or the applicable ESU-protected legacy version. Run Microsoft Exchange Health Checker after maintenance to confirm patch and configuration status. If patching cannot be completed immediately, disable OWA Light as instructed by Microsoft and reduce unnecessary internet exposure of Exchange services and management interfaces. Organisations still operating Exchange 2016/2019 should plan migration to a supported platform.
Exchange Online and hybrid environments
Pure Exchange Online customers do not install these on-premises server patches themselves. Hybrid organisations must still update local Exchange servers and relevant management components that remain deployed.
vCDC assessment
Priority: HIGH. This is not one single unauthenticated zero-day, but a security update for a highly privileged and business-critical platform. Internet-facing on-premises Exchange systems should be kept current and unnecessary exposure removed.





