Nearly 22,000 Internet-Exposed Microsoft Exchange Servers Remain Unpatched Against CVE-2026-62911
Approximately 22,000 Microsoft Exchange servers accessible online remain unpatched against a high-severity authentication bypass vulnerability that could allow attackers to take control of users’ mailboxes.
Tracked as CVE-2026-62911, the vulnerability was reported by Orange Tsai of the DEVCORE Research Team. It affects Microsoft Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE).
An attacker with basic privileges on a vulnerable server could exploit the flaw remotely through a low-complexity attack that requires user interaction. Microsoft describes the issue as a Capture Replay authentication bypass that enables an authorized attacker to escalate privileges over the network.
“An attacker can take over any Exchange user’s mailbox, allowing the attacker to send emails, read emails, and download attachments,” Microsoft said after releasing security updates during the August 2026 Patch Tuesday updates.
Microsoft has not yet updated or confirmed the CVE-2026-62911 advisory. However, the Netherlands National Cyber Security Center (NCSC-NL) reported last week that proof-of-concept exploit code for the vulnerability is already available online.
“Microsoft has provided updates to address the vulnerabilities. Please install these updates as soon as possible,” the NCSC-NL warned.
The agency also noted that Exchange Server 2016 and Exchange Server 2019 receive security updates only through the Extended Security Updates (ESU) program. Organizations still using these versions should restrict server access to internal networks and replace the systems when possible.
On Tuesday, threat intelligence organization Shadowserver warned that 21,899 IP addresses associated with Microsoft Exchange Server fingerprints were still unpatched and exposed to the internet.
Most of the exposed systems were located in the United States, with approximately 6,200 IP addresses, and Germany, with approximately 5,100.

Although CVE-2026-62911 has not been linked to attacks in the wild, Microsoft recently patched another Exchange Server vulnerability, CVE-2026-42897. The flaw was exploited in June as part of a cross-site scripting (XSS) campaign targeting Outlook Web Access users.
The Cybersecurity and Infrastructure Security Agency (CISA) also added CVE-2026-42897 to its Known Exploited Vulnerabilities catalog on May 15. The agency ordered U.S. federal agencies to patch affected servers within two weeks.
Since November 2021, CISA has added 20 Microsoft Exchange Server vulnerabilities to its Known Exploited Vulnerabilities catalog. Fourteen of those vulnerabilities have been identified as being used in ransomware attacks.
In October, following Microsoft’s announcement that support for Exchange Server 2016 and Exchange Server 2019 was ending, CISA and the National Security Agency (NSA) issued joint guidance for hardening Microsoft Exchange servers against cyberattacks.
Microsoft also warned customers two months ago that security updates for Exchange Server 2016 and Exchange Server 2019 will stop being distributed through the Extended Security Updates program in October 2026.
The overall prevention score can obscure what happens after an attacker gains initial access. When threat actors use valid credentials, security defenses can weaken significantly.
The Blue Report 2026 evaluates defense techniques across technologies using 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com



