Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes, according to data from the threat monitoring group Shadowserver.
Tracked as CVE-2026-62911 and reported by Orange Tsai of the DEVCORE Research Team, the flaw affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE). Microsoft patched the vulnerability during the August 2026 Patch Tuesday, describing it as an “authentication bypass by capture-replay” that allows an authorized attacker to elevate privileges over a network. “The attacker would be able to take over the mailboxes of all Exchange users, attackers can send emails, read emails, download attachments,” Microsoft said.
Although the patch has been available for several weeks, exploit code for CVE-2026-62911 has already been published online, the Netherlands National Cyber Security Centre (NCSC-NL) reported last week. “Microsoft has made updates available to address the vulnerabilities. Install these updates as soon as possible,” NCSC-NL warned. The agency also noted that Exchange Server 2016 and 2019 only receive security updates via the Extended Security Updates Program (ESU) and urged administrators to restrict access or replace older versions.
Shadowserver identified 21,899 IP addresses bearing an unpatched Exchange Server fingerprint that are still accessible from the internet, with the largest concentrations in the United States (6,200) and Germany (5,100). Germany’s Federal Office for Information Security (BSI) also issued an alert on Friday, underscoring the urgency for organizations to apply the security update.
The large number of unpatched servers, combined with publicly available exploit code, heightens the risk of wide-scale mailbox takeover attacks. Administrators are advised to immediately apply the August 2026 security updates and, for unsupported versions, consider upgrading or restricting external access.