Back to feed

Nearly 22,000 Microsoft Exchange servers exposed to mailbox hijack attacks

2 min
Nearly 22,000 Microsoft Exchange servers exposed to mailbox hijack attacks

This digest was compiled by AI from multiple sources — links to the originals are below.

Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, an authentication bypass flaw that allows attackers to hijack all user mailboxes. Shadowserver found 21,899 exposed IP addresses, most in the United States and Germany. Public exploit code is already available, raising the risk of widespread attacks.

Key Facts

  • Shadowserver found 21,899 IP addresses with unpatched Microsoft Exchange servers exposed online, most in the United States (6,200) and Germany (5,100).
  • CVE-2026-62911 affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE).
  • Microsoft patched the vulnerability on August 11, 2026, during its August Patch Tuesday.
  • The Netherlands National Cyber Security Centre (NCSC-NL) reported that exploit code for CVE-2026-62911 is already available online.
  • Germany's Federal Office for Information Security (BSI) warned that around 85% of on-premises Exchange servers in Germany remain vulnerable.

Vulnerability Details

CVE-2026-62911 is an authentication bypass by capture-replay vulnerability in Microsoft Exchange Server. Microsoft stated that an authorized attacker can elevate privileges over a network and take over mailboxes of all Exchange users, enabling them to send emails, read emails, and download attachments. The flaw affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE). DEVCORE Research Team's Orange Tsai reported the vulnerability to Microsoft.

Exposure and Exploitation

Shadowserver identified 21,899 IP addresses with vulnerable Exchange servers, with 6,200 in the United States and 5,100 in Germany. The Netherlands National Cyber Security Centre (NCSC-NL) raised the priority level to high after proof-of-concept code was published online. Germany's Federal Office for Information Security (BSI) reported that approximately 85% of on-premises Exchange servers in Germany are still vulnerable. Microsoft has not yet updated the CVE-2026-62911 advisory to confirm active exploitation in the wild.

Mitigation and Response

Microsoft released security updates for CVE-2026-62911 on August 11, 2026, and NCSC-NL advised installing them as soon as possible. Exchange Server 2016 and 2019 receive security updates only through the Extended Security Updates (ESU) program. NCSC-NL recommended that organizations using unsupported versions restrict server access to internal networks or replace the servers. CISA and the NSA released joint guidance in October 2025 on hardening Exchange servers after Exchange 2016 and 2019 reached end of support.

2 sources

Time · lag behind first