View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Public PoC demonstrates Microsoft Exchange CVE-2026-62911 RCE chain

๐Ÿšจ ACTIVE EXPLOITATION

  • Fake Claude Opus 5 App Distributes RevStealer Infostealer
    RevStealer is being distributed through a fake Claude Opus 5 Windows app.
    • Windows users downloading unofficial Claude desktop software are targeted.
    • RevStealer steals browser data, credentials, session cookies, password-manager records, VPN data and cryptocurrency wallet material.
    • The lure is a roughly 101 MB archive named ClaudeOpus5-desktop.zip from GitHub repositories and game-cheat websites.
    • A trojanized 64-bit Electron app decrypts an AES-256-CBC payload into AppData and launches it as a hidden process.
    • Anti-analysis features include sandbox checks, CAPTCHA gating, 14 indirect syscalls, in-memory encrypted exfiltration and Polygon smart-contract C2 fallback.
      ๐Ÿ“„ https://www.morphisec.com/blog/revstealer-silence-is-its-greatest-weapon/ ยท ๐Ÿ“Ž https://www.scworld.com/news/revstealer-malware-spread-through-fake-claude-opus-5-download ยท ๐Ÿ‘ via https://cybersecuritynews.com/revstealer-inside-fake-claude/, https://www.cryptika.com/hackers-hide-revstealer-inside-fake-claude-opus-5-app-to-steal-passwords-and-crypto/

๐Ÿ’ฅ BREACHES & INCIDENTS

  • Attackers Stole METR API Key and Attempted to Access Public Infrastructure
    Attackers stole a METR API key and probed its public infrastructure.
    • METR, a nonprofit evaluating frontier AI models, was targeted in two incidents in 2026.
    • A stolen API key was used to consume about $600,000 worth of public-model credits.
    • Attackers exposed a publicly accessible agent dashboard through a fail-open authentication flaw and added an SSH key.
    • A later campaign used credential stuffing, OAuth attempts, service scanning, and staff phishing.
    • Attackers probed a transcript viewer endpoint, but METR found no evidence of non-public data access.
      ๐Ÿ“„ https://metr.org/blog/2026-08-31-security-update ยท ๐Ÿ“Ž https://thehackernews.com/2026/09/attackers-steal-metr-api-key-and.html ยท ๐Ÿ‘ via https://thehackernews.com/2026/09/attackers-steal-metr-api-key-and.html, https://infosec.exchange/@metacurity/117195543622756441

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Public PoC demonstrates Microsoft Exchange CVE-2026-62911 RCE chain CVE-2026-62911
    A public PoC demonstrates a pre-authentication RCE chain targeting vulnerable on-premises Exchange Server.

    • Affects on-premises Exchange Server 2016 CU23, 2019 CU14/CU15, and Subscription Edition RTM.
    • CVE-2026-62911 is a capture-replay authentication-bypass privilege-escalation flaw that can contribute to SYSTEM-level RCE when chained with file-write weaknesses.
    • The PoC uses PetitPotam/MS-EFSR to coerce NTLM authentication and relays it to the MRSProxy endpoint without EPA channel binding.
    • WCF MRSProxy methods IMailbox_Config6 and IMailbox_Connect write an ASPX webshell to an IIS-accessible directory.
    • Targets and artifacts include /Microsoft.Exchange.MailboxReplicationService.ProxyService, /EWS/MRSProxy.svc, SMB port 445, and c681d488-d850-11d0-8c52-00c04fd90f7e.
      ๐Ÿ“„ https://github.com/hypnguyen1209/CVE-2026-62911 ยท ๐Ÿ“Ž https://cybersecuritynews.com/poc-microsoft-exchange-server-pre-auth-rce/ ยท ๐Ÿ‘ via https://cybersecuritynews.com/poc-microsoft-exchange-server-pre-auth-rce/, https://www.cryptika.com/public-poc-released-for-microsoft-exchange-server-pre-auth-rce-vulnerability/
  • GeoNetwork Pre-Auth RCE Chain Affected 121 Government Deployments
    GeoNetwork was vulnerable to pre-authenticated remote code execution.

    • GeoNetwork deployments, including 121 government installations, were affected.
    • Four vulnerabilities enabled unauthenticated file upload and unsafe XSLT processing.
    • The attack chain could lead to remote code execution without prior authentication.
    • All affected deployments were reported as patched.
      ๐Ÿ“Ž https://ethiack.com/info-hub/research/geonetwork-preauth-RCE ยท ๐Ÿ‘ via https://www.reddit.com/r/netsec/comments/1w46vwa/geonetwork_preauth_rce_via_unauthenticated_file/

๐Ÿ“‹ ADVISORIES

  • ๐Ÿ“„ Source for Live Composer 2.1.19 and earlier expose WordPress sites to stored XSS โ€” wordfence.com

๐Ÿ”“ CVEs & KEV

  • CVE-2026-84165 โ€” CVSS 8.7 โ€” Lack of authorisation in OpenNebula by OpenNebula SystemsA vulnerability rela...

  • CVE-2026-59681 โ€” CVSS 8.7 โ€” yast2-auth-client: OS command injection via unsanitized Organizational Unit /...

  • CVE-2026-59680 โ€” CVSS 8.6 โ€” yast2-users: OS command injection via LDAP-supplied shadowLastChange/shadowEx...

  • CVE-2026-25706 โ€” CVSS 7.5 โ€” yast2-samba-client: OS command injection via attacker-controlled Organization...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check