Nearly 22,000 Microsoft Exchange servers remain exposed to a mailbox-hijacking flaw with public exploit code

Nearly 22,000 Microsoft Exchange servers exposed to the internet remain unpatched against a high-severity authentication bypass vulnerability that lets attackers hijack every mailbox on the machine, according to a scan published Tuesday by threat-monitoring group Shadowserver. Microsoft shipped a fix for the flaw during its August 2026 Patch Tuesday release, but adoption has lagged badly enough that two national cybersecurity agencies have issued their own public warnings in the past week.
The vulnerability, tracked as CVE-2026-62911, was discovered by Orange Tsai of DEVCORE Research Team and affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition. Microsoft describes it as an “authentication bypass by capture-replay” flaw that lets an attacker with only basic privileges on the target server escalate to full control of every mailbox — reading email, sending as any user, and downloading attachments — in an attack Microsoft rates as low-complexity, though it does require some user interaction.
Exploit code is already circulating
Microsoft's own advisory has not yet been updated to confirm active exploitation, but the Netherlands' National Cyber Security Centre (NCSC-NL) reported last week that working exploit code for CVE-2026-62911 is already available online — the gap between “patch exists” and “attackers have a ready-made tool” that turns a disclosed vulnerability into an active threat.
Shadowserver's scan found 21,899 IP addresses still carrying an exposed, unpatched Exchange Server fingerprint, concentrated heavily in the United States (roughly 6,200 servers) and Germany (roughly 5,100). Germany's Federal Office for Information Security (BSI) put a sharper number on its own exposure Friday, warning that around 85% of all on-premises Exchange servers in the country remain vulnerable — a striking figure for a patch that has been available for weeks.
Why on-prem Exchange keeps ending up here
This is not an isolated incident. Since November 2021, CISA has added 20 separate Microsoft Exchange Server vulnerabilities to its Known Exploited Vulnerabilities catalog, 14 of which were also used in ransomware campaigns. Part of the pattern is structural: Exchange Server 2016 and 2019 reached end of mainstream support in 2026, and organizations still running them now depend on Microsoft's Extended Security Updates (ESU) program — support that itself stops shipping in October 2026. NCSC-NL's advisory pointedly recommended that any organization still running an unsupported version restrict the server to internal-only access, or replace it outright, rather than continue relying on patches that are running out.
For organizations that can't retire on-premises Exchange immediately, CISA and the NSA published joint hardening guidance after the 2026 end-of-support milestone, covering the baseline steps — network segmentation, restricting internet exposure, enforcing multi-factor authentication on administrative accounts — that reduce the odds a single unpatched CVE becomes a full mailbox compromise.
What to check right now
Administrators running Exchange Server 2016, 2019, or Subscription Edition should confirm the August 2026 security update is installed, verify whether their server is reachable from the public internet at all, and treat any server that can't be patched immediately as a priority candidate for network isolation. With exploit code already public and tens of thousands of servers still exposed, the window between disclosure and mass exploitation on this one is likely to be short.
Originally reported by BleepingComputer. Read the original article for additional details.
View original source