Nearly 22,000 Microsoft Exchange servers exposed to the internet remain unpatched against a high-severity authentication bypass vulnerability. This flaw allows attackers to hijack all user mailboxes on affected servers. The vulnerability is classified as high-severity and represents a significant risk to organizations still running unpatched versions. The large number of exposed servers indicates widespread failure to apply available security updates. Successful exploitation could lead to full compromise of email communications, data exfiltration, and further lateral movement within affected organizations.
CVE-2026-62911 is a high-severity authentication bypass vulnerability in Microsoft Exchange Server that works via a capture-replay mechanism, allowing an authorized attacker to elevate privileges over a network. The flaw affects Exchange Server 2016, 2019, and Subscription Edition (SE). Attackers with basic (low) privileges on the targeted server can exploit it in low-complexity attacks that require user interaction. Successful exploitation allows the attacker to take over all user mailboxes, enabling them to send emails, read emails, and download attachments. The vulnerability was reported by DEVCORE Research Team's Orange Tsai and patched during the August 2026 Patch Tuesday. As of late August 2026, approximately 21,899 IP addresses running unpatched Microsoft Exchange servers remain publicly exposed online, with the highest concentrations in the United States (6,200) and Germany (5,100). Exploit code for CVE-2026-62911 has been reported as publicly available online by NCSC-NL. Germany's BSI reported that approximately 85% of all on-premises Exchange servers in Germany remain vulnerable. A separate vulnerability, CVE-2026-42897 (XSS targeting Outlook Web Access users), was patched in June and confirmed exploited in the wild; it was added to CISA's Known Exploited Vulnerabilities Catalog. Since November 2021, CISA has added 20 Microsoft Exchange Server vulnerabilities to its KEV catalog, 14 of which were flagged as abused in ransomware attacks.
1. Apply the August 2026 Patch Tuesday security update for CVE-2026-62911 immediately to all Microsoft Exchange Server installations. 2. For Exchange Server 2016 and 2019, ensure the server is accessible only internally (not exposed to the internet) as these versions only receive security updates via the Extended Security Updates Program (ESU). Replace these end-of-life versions if possible. 3. If using Exchange Server 2016 or 2019, enroll in the Extended Security Updates (ESU) program to continue receiving security updates; note that ESU for these versions ends in October 2026. 4. Use Shadowserver's dashboard to check if your Exchange servers appear as unpatched and publicly exposed. 5. Follow joint CISA and NSA guidance on hardening Exchange servers against attacks. 6. Monitor CISA's Known Exploited Vulnerabilities Catalog for any updates regarding active exploitation of CVE-2026-62911. 7. U.S. government agencies should ensure CVE-2026-42897 (already in KEV catalog) is patched per CISA directives. 8. Consider migrating to Exchange Online or a supported on-premises version to reduce ongoing attack surface.