Nearly 22,000 Exchange Servers Are Still Open to a Flaw That Hands Over Every Mailbox

CVE-2026-62911 lets an attacker take over Exchange mailboxes. Microsoft has patched it, but about 22,000 servers remain exposed.

Get Advisory Support
High CVE-2026-62911

CVE-2026-62911 is an authentication bypass by capture-replay in Microsoft Exchange Server, reported by Orange Tsai of the DEVCORE Research Team and patched by Microsoft in the August 2026 Patch Tuesday release. Microsoft's own description of the impact is unusually direct: the attacker "would be able to take over the mailboxes of all Exchange users, attackers can send emails, read emails, download attachments." It affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition. Exploitation requires an attacker to already hold basic privileges on the targeted server and involves user interaction, which is why it is rated high rather than critical — but the Netherlands National Cyber Security Centre has reported that exploit code is already circulating publicly, and that changes the calculus. On September 1, 2026 the Shadowserver Foundation counted 21,899 IP addresses with an Exchange Server fingerprint still unpatched and exposed online, most of them in the United States, at roughly 6,200, and Germany, at roughly 5,100. Germany's Federal Office for Information Security warned that around 85 percent of on-premises Exchange servers in that country remain vulnerable. Microsoft has not confirmed exploitation in the wild for this particular CVE at the time of writing. The date that should concern anyone still running Exchange on premises is October 2026, when security updates for Exchange 2016 and 2019 stop shipping through the Extended Security Update program entirely.

Recommended action: Confirm this week whether you still have an Exchange server on premises. Many clinics, municipalities, and small regulated organizations in Puerto Rico moved mail to Microsoft 365 years ago but left one Exchange server running for hybrid identity management or address book synchronization, and that server is frequently forgotten, rarely patched, and still reachable. If you have one, apply the August 2026 Exchange security update, and verify that Exchange 2016 and 2019 systems are actually enrolled in the Extended Security Update program, because unenrolled servers received nothing. Then take Outlook Web Access and the Exchange Control Panel off the public internet: put them behind a VPN or restrict them to trusted internal addresses. Enforce multifactor authentication for every account with a mailbox and for every administrator, and disable legacy authentication protocols, which quietly bypass MFA. Because the flaw hands an attacker mailbox contents, treat detection as a parallel task rather than a later one: review mailbox forwarding rules, inbox rules, delegate permissions, and mailbox audit logs for changes nobody requested, and look specifically for rules that forward externally or silently move messages to an obscure folder. In a healthcare setting, mailboxes are usually full of protected health information — referrals, lab results, prior authorization threads, patient questions — so unauthorized access to a mailbox is a security incident under 45 CFR §164.308(a)(6) and requires a documented risk assessment under 45 CFR §164.402 to determine whether it is a reportable breach. Finally, put October 2026 on the leadership calendar now. When Extended Security Updates end for Exchange 2016 and 2019, an unmigrated server stops receiving fixes for flaws exactly like this one, and migration is a project measured in months, not weekends.
Sources: Microsoft Security Response Center advisory for CVE-2026-62911, NIST National Vulnerability Database, Netherlands National Cyber Security Centre (NCSC-NL) alert, Shadowserver Foundation scan data, Germany's Federal Office for Information Security (BSI), BleepingComputer (September 1, 2026).

← All security bulletins

Bulletins summarize publicly reported information for awareness and are not a substitute for vendor advisories or a tailored assessment.

Worried about a bulletin above?

We can assess your exposure to the threats above and other active campaigns, and help you remediate quickly.

Request an Exposure Check