Nearly 22,000 Microsoft Exchange servers around the world are still exposed to a high-severity flaw that lets an attacker take over every mailbox on an affected server, according to internet scan data reported by BleepingComputer and Help Net Security this week. Microsoft shipped a fix for the bug back on August 11, 2026, but adoption has been slow, and working exploit code for it is now circulating publicly.
The vulnerability, tracked as CVE-2026-62911, affects on-premises Microsoft Exchange Server 2016, 2019, and the newer Subscription Edition. Microsoft’s own advisory describes it as an authentication bypass that lets someone who already has some level of network access carry out what is known as a capture-replay attack: intercepting valid authentication data and reusing it to impersonate another user. Once that works, Microsoft has said the attacker “would be able to take over the mailboxes of all Exchange users,” reading messages, sending mail as someone else, and downloading attachments. The flaw carries a CVSS score of 8.0, which most scoring systems classify as high severity rather than the maximum critical tier, though several outlets have still described it in stronger terms given the scale of what a successful attack allows.
The bug was found and reported by Orange Tsai of the DEVCORE Research Team, a researcher with a long track record of uncovering serious Exchange vulnerabilities, including some of the flaws exploited in the 2021 ProxyLogon attacks. Microsoft has not said it has seen CVE-2026-62911 exploited in the wild yet, but the Dutch National Cyber Security Centre, NCSC-NL, flagged in late August that proof-of-concept exploit code for the bug is now publicly available, which sharply raises the odds of real-world attacks in the near term.
Scans cited by BleepingComputer put the number of unpatched, internet-facing Exchange servers at close to 22,000 globally. The United States accounts for roughly 6,200 of those systems and Germany for about 5,100, the two largest concentrations identified. Germany’s federal cybersecurity agency, the BSI, went further, estimating that around 85 percent of the on-premises Exchange servers still running in the country have not been patched against this flaw, a figure that points to how many organizations have been slow to act even after a fix was made available.
Complicating matters, Exchange Server 2016 and 2019 are approaching the end of extended support in October 2026, after which they will no longer receive security updates at all unless organizations enroll in Microsoft’s paid Extended Security Updates program. NCSC-NL’s guidance to affected organizations is direct: install the security update as soon as possible, restrict Exchange server access to internal networks where full patching is not immediately possible, and begin planning to replace unsupported versions rather than continuing to run them past their support window.
For IT administrators still running on-premises Exchange, the practical takeaway is straightforward. If the August 2026 security update has not been applied yet, it should be treated as urgent, not routine, maintenance. Organizations that cannot patch immediately should limit external access to their Exchange infrastructure and monitor authentication logs for unusual activity while a permanent fix is put in place.
Source: This story is based on reporting from BleepingComputer and Help Net Security, along with Microsoft’s official advisory for CVE-2026-62911.
