Skip to main content
CybersecurityVulnerability Management

Unpatched Microsoft Exchange Servers Exposed to Hijack Attacks

Dimly lit server room with rows of racks, one foreground rack with a warning sign.

21,899 internet-facing Microsoft Exchange servers remain unpatched against CVE-2026-62911, a high‑severity authentication‑bypass flaw that lets an attacker hijack every mailbox on a vulnerable system.

CVE-2026-62911: an authentication bypass that can seize mailboxes

The vulnerability, tracked as CVE-2026-62911 and reported by DEVCORE Research Team's Orange Tsai, affects Microsoft Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE). Microsoft said it patched the flaw during the August 2026 Patch Tuesday. In Microsoft’s description of the fix: “Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network,” and “The attacker would be able to take over the mailboxes of all Exchange users, attackers can send emails, read emails, download attachments.”

Scale and geography: nearly 22,000 exposed IP addresses

Security watchdog Shadowserver reported that 21,899 IP addresses with a Microsoft Exchange Server fingerprint are still unpatched and exposed online. Shadowserver’s breakdown places most of those addresses in the United States (6,200) and Germany (5,100). The raw count underscores both the scale of potentially vulnerable infrastructure and the uneven geographic distribution of exposed servers.

Exploit code availability and the current threat posture

While Microsoft has not yet updated its CVE advisory to confirm active exploitation, the Netherlands National Cyber Security Centre (NCSC‑NL) reported that exploit code for CVE-2026-62911 is already available online. NCSC‑NL warned: “Microsoft has made updates available to address the vulnerabilities. Install these updates as soon as possible.” The center also noted that Exchange Server 2016 and 2019 only receive security updates via the Extended Security Updates Program (ESU), advising administrators using those versions to ensure servers are accessible only internally and to replace them if possible.

The record of recent activity increases urgency. Microsoft patched another Exchange Server vulnerability, CVE-2026-42897, in June after it was exploited in cross‑site scripting (XSS) attacks targeting Outlook Web Access users. The Cybersecurity and Infrastructure Security Agency (CISA) added that June flaw to its Known Exploited Vulnerabilities Catalog on May 15 and ordered U.S. government agencies to patch their servers within two weeks. Since November 2021, CISA has added 20 Microsoft Exchange Server vulnerabilities to its list of actively exploited security issues, 14 of them also flagged as abused in ransomware attacks.

Guidance from Microsoft, NCSC‑NL, Shadowserver and CISA

The public guidance is straightforward and consistent across the organizations named in reporting: Microsoft released updates to address the vulnerability during the August Patch Tuesday; NCSC‑NL urged immediate installation of those updates and special handling for Exchange 2016 and 2019 installations that rely on ESU; Shadowserver published counts of unpatched, internet‑exposed servers; and CISA’s prior actions on Exchange vulnerabilities show the agency’s willingness to add Exchange flaws to its Known Exploited Vulnerabilities Catalog and mandate quick remediation for federal agencies.

What this means for technologists, U.S. government agencies, and enterprise owners

  • Technologists and security teams: install the August 2026 updates as soon as practical, monitor for capture‑replay indicators, and treat internet‑exposed Exchange fingerprints as high priority—especially where servers run 2016 or 2019 under ESU.
  • U.S. government agencies: CISA’s past enforcement—ordering two‑week remediation for CVE-2026-42897 and adding Exchange flaws to its Known Exploited Vulnerabilities Catalog—signals that agency networks may face directive timelines if this CVE is similarly escalated.
  • Enterprise owners and procurement leaders running Exchange 2016 or 2019: follow NCSC‑NL’s advice to restrict external access or replace these servers where possible; note that Microsoft two months ago reminded customers Exchange 2016 and 2019 security updates will stop shipping through the ESU program in October 2026.

The technical reality here is blunt: capture‑replay authentication bypasses let attackers operate with legitimate credentials, and once attackers possess valid credentials “prevention drops sharply,” as one recent industry measurement put it. Nearly 22,000 exposed IPs, available exploit code, and a recent history of exploited Exchange flaws present a compressing window for defenders. Will owners apply the available updates and hardening advice quickly enough to stay ahead of opportunistic exploitation? For now, the publicly reported facts offer a clear prescription—patch, restrict exposure, and replace older, ESU‑dependent servers where feasible.

Original story