CVE-2026-62911 Exchange Auth Bypass Post-Exploitation Fingerprint
Detects post-exploitation indicators of CVE-2026-62911, an authentication-bypass-by-capture-replay vulnerability in Microsoft Exchange. The rule identifies anomalous behavior following a potential bypass: either the assignment of the ApplicationImpersonation management role or a single impersonation session accessing an abnormally high number of distinct mailboxes (FolderBind, MessageBind, or SendAs).
Sigma

