Microsoft Exchange Vulnerability CVE-2026-62911: What Administrators Should Do and How Zscaler Can Help
Zscaler, Thursday, September 3rd, 2026
Zscaler covers CVE-2026-62911, a high-severity Exchange Server authentication bypass, with patching steps and attack surface guidance.
Microsoft's August 2026 Patch Tuesday included a fix for CVE-2026-62911, a high-severity authentication bypass affecting Exchange Server 2016, 2019 and Subscription Edition.
Zscaler walks administrators through the immediate response, including the patching steps required to close the exposure.
It then makes the longer-term argument that internet-exposed Exchange infrastructure is the underlying problem and that a zero trust architecture eliminates that attack surface rather than repeatedly patching it.
The post is aimed at administrators who need both the tactical fix and a structural answer.