
Nearly 22,000 Microsoft Exchange servers remain exposed to a mailbox-hijacking flaw with public exploit code
A high-severity authentication bypass in Exchange Server 2016, 2019, and Subscription Edition lets attackers take over any mailbox on a vulnerable server. Microsoft patched it in August, but Shadowserver found nearly 22,000 unpatched servers still exposed online — 85% of Germany's on-premises fleet among them.




