Nearly 22,000 Microsoft Exchange Servers Still Unpatched Against Critical Hijack Vulnerability

Exploit code for CVE-2026-62911 is already online, with most exposed servers in the US and Germany

edit
By LineZotpaper
Published
Read Time2 min
Over 21,000 Microsoft Exchange servers remain exposed and unpatched against a high-severity authentication bypass vulnerability (CVE-2026-62911) that could let attackers hijack all user mailboxes, security researchers warned this week.

Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes, according to data from the threat monitoring group Shadowserver.

Tracked as CVE-2026-62911 and reported by Orange Tsai of the DEVCORE Research Team, the flaw affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE). Microsoft patched the vulnerability during the August 2026 Patch Tuesday, describing it as an “authentication bypass by capture-replay” that allows an authorized attacker to elevate privileges over a network. “The attacker would be able to take over the mailboxes of all Exchange users, attackers can send emails, read emails, download attachments,” Microsoft said.

Although the patch has been available for several weeks, exploit code for CVE-2026-62911 has already been published online, the Netherlands National Cyber Security Centre (NCSC-NL) reported last week. “Microsoft has made updates available to address the vulnerabilities. Install these updates as soon as possible,” NCSC-NL warned. The agency also noted that Exchange Server 2016 and 2019 only receive security updates via the Extended Security Updates Program (ESU) and urged administrators to restrict access or replace older versions.

Shadowserver identified 21,899 IP addresses bearing an unpatched Exchange Server fingerprint that are still accessible from the internet, with the largest concentrations in the United States (6,200) and Germany (5,100). Germany’s Federal Office for Information Security (BSI) also issued an alert on Friday, underscoring the urgency for organizations to apply the security update.

The large number of unpatched servers, combined with publicly available exploit code, heightens the risk of wide-scale mailbox takeover attacks. Administrators are advised to immediately apply the August 2026 security updates and, for unsupported versions, consider upgrading or restricting external access.

§

Analysis

Why This Matters

  • Organizations running unpatched Exchange servers face imminent risk of mailbox hijacking, potentially leading to data theft, business email compromise, and further network intrusion.
  • With exploit code publicly available, the window to patch before active attacks begin is rapidly closing.
  • The affected versions include Exchange Server 2016 and 2019, which are nearing or already past mainstream support, relying on paid Extended Security Updates.

Background

Microsoft Exchange Server has been a frequent target for attackers, with vulnerabilities in recent years leading to large-scale breaches (e.g., ProxyLogon, ProxyShell). On-premises Exchange deployments often remain unpatched due to complexity, compatibility concerns, or legacy status. The current vulnerability is an authentication bypass via capture-replay, meaning an attacker who can intercept or replay valid authentication tokens can gain full mailbox access.

Key Perspectives

Microsoft: The vendor released a patch in August 2026 and described the flaw as critical, but has not yet confirmed exploit code availability in its advisory. NCSC-NL and BSI: National cybersecurity agencies are urging immediate patching and warning that unsupported Exchange versions (2016/2019) should be isolated or replaced as soon as possible. Shadowserver: The monitoring group’s scan data highlights the persistent risk, showing thousands of servers remain exposed weeks after patch release.

What to Watch

  • Shadowserver’s daily scan updates to see if the count of unpatched servers is decreasing.
  • Reports of active exploitation or ransomware groups leveraging CVE-2026-62911 in campaigns.
  • Whether Microsoft expands its advisory or provides additional mitigation guidance for administrators who cannot patch immediately.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.