Skip to content
Tech News
← Back to articles

Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

read original more articles
Why This Matters

The widespread exposure of nearly 22,000 unpatched Microsoft Exchange servers to a critical vulnerability underscores the urgent need for organizations to prioritize timely security updates. This flaw allows attackers to hijack mailboxes, potentially leading to data breaches and compromised communications, highlighting the ongoing risks of unpatched enterprise systems. For consumers and businesses alike, this emphasizes the importance of proactive cybersecurity measures and regular patch management to safeguard sensitive information.

Key Takeaways

Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes.

Tracked as CVE-2026-62911 and reported by DEVCORE Research Team's Orange Tsai, this security flaw affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) software. Threat actors with basic privileges on the targeted server can exploit it in low-complexity attacks that require user interaction.

"Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network," Microsoft said when it patched the vulnerability during the August 2026 Patch Tuesday. "The attacker would be able to take over the mailboxes of all Exchange users, attackers can send emails, read emails, download attachments."

While Microsoft has yet to update the CVE-2026-62911 advisory to confirm it, the Netherlands National Cyber Security Centre (NCSC-NL) reported last week that exploit code for this vulnerability is already available online.

"Microsoft has made updates available to address the vulnerabilities. Install these updates as soon as possible," NCSC-NL noted. "Exchange Server 2016 and 2019 only receive security updates via the Extended Security Updates Program (ESU). Are you using one of these versions? If so, ensure that the server is accessible only internally and replace it if possible."

On Tuesday, threat security watchdog group Shadowserver said that it found 21,899 IP addresses with a Microsoft Exchange Server fingerprint that are still unpatched and exposed online, most of them in the United States (6,200) and Germany (5,100).

Unpatched Exchange servers exposed online (Shadowserver)

Germany's Federal Office for Information Security (BSI) also warned on Friday (as first spotted by Heise) that around 85% of all on-premises Exchange servers in Germany are still vulnerable to this vulnerability.

While CVE-2026-62911 has yet to be flagged as abused in the wild, Microsoft patched another Exchange Server vulnerability (CVE-2026-42897) in June that was exploited in cross-site scripting (XSS) attacks targeting Outlook Web Access users.

The Cybersecurity and Infrastructure Security Agency (CISA) also added the CVE-2026-42897 flaw to its Known Exploited Vulnerabilities Catalog on May 15 and ordered U.S. government agencies to patch their servers within two weeks.

... continue reading