Thousands of Exchange Servers Remain Vulnerable to Critical Authentication Bypass
A high-severity authentication bypass vulnerability, **CVE-2026-62911**, continues to plague nearly 22,000 **Microsoft Exchange** servers exposed online. This flaw allows attackers with basic privileges to hijack all user mailboxes, posing a significant threat to organizational security and data integrity. Despite patches being released in August 2026, a substantial number of systems remain unpatched, with exploit code now publicly available.
Nearly 22,000 **Microsoft Exchange** servers, still exposed online, remain unpatched against a critical authentication bypass vulnerability. This flaw, tracked as **CVE-2026-62911**, allows attackers to completely compromise all user mailboxes.
### The Vulnerability: CVE-2026-62911
Reported by **DEVCORE Research Team**'s **Orange Tsai**, **CVE-2026-62911** impacts **Exchange Server 2016**, **Exchange Server 2019**, and **Exchange Server Subscription Edition (SE)**. It's an authentication bypass by capture-replay vulnerability that enables an authorized attacker to escalate privileges over a network. **Microsoft** officially patched this vulnerability during the August 2026 Patch Tuesday, stating that an attacker could "take over the mailboxes of all Exchange users, attackers can send emails, read emails, download attachments."
### Exploit Code Now Publicly Available
While **Microsoft** has yet to update its advisory, the **Netherlands National Cyber Security Centre (NCSC-NL)** confirmed last week that exploit code for **CVE-2026-62911** is already available online. This significantly increases the urgency for organizations to apply the necessary updates.
### Thousands of Unpatched Servers Detected
On Tuesday, the cybersecurity watchdog group **Shadowserver** reported identifying 21,899 IP addresses with **Microsoft Exchange Server** fingerprints that are still unpatched and exposed to the internet. The majority of these vulnerable servers are located in the United States (6,200) and Germany (5,100).

*Unpatched Exchange servers exposed online (Shadowserver)*
Germany's **Federal Office for Information Security (BSI)** also issued a warning, noting that approximately 85% of all on-premises **Exchange** servers in Germany are still susceptible to this vulnerability.
### A History of Exchange Vulnerabilities
This isn't an isolated incident for **Microsoft Exchange**. In June, **Microsoft** patched another **Exchange Server** vulnerability, **CVE-2026-42897**, which was actively exploited in cross-site scripting (XSS) attacks targeting **Outlook Web Access** users. The **Cybersecurity and Infrastructure Security Agency (CISA)** added **CVE-2026-42897** to its Known Exploited Vulnerabilities Catalog on May 15, mandating U.S. government agencies to patch their servers within two weeks.
Since November 2021, **CISA** has listed 20 **Microsoft Exchange Server** vulnerabilities in its catalog of actively exploited security issues, with 14 of these also being flagged as abused in ransomware attacks.
### End-of-Support and Hardening Guidance
In October, following the end-of-support announcement for **Exchange 2016** and **2019**, **CISA** and the **National Security Agency (NSA)** released joint guidance on hardening **Exchange** servers against potential attacks. Furthermore, **Microsoft** reminded customers two months ago that **Exchange 2016** and **Exchange 2019** security updates through the Extended Security Update (ESU) program will cease in October 2026.
Given the constant threat landscape and the availability of exploit code, immediate patching and adherence to security best practices are paramount for organizations utilizing **Microsoft Exchange**.