BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
BleepingComputer · Sep 1, 2026 · 2 min read · Original story

Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes.

Tracked as CVE-2026-62911 and reported by DEVCORE Research Team's Orange Tsai, this security flaw affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) software. Threat actors with basic privileges on the targeted server can exploit it in low-complexity attacks that require user interaction.

"Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network," Microsoft said when it patched the vulnerability during the August 2026 Patch Tuesday. "The attacker would be able to take over the mailboxes of all Exchange users, attackers can send emails, read emails, download attachments."

While Microsoft has yet to update the CVE-2026-62911 advisory to confirm it, the Netherlands National Cyber Security Centre (NCSC-NL) reported last week that exploit code for this vulnerability is already available online.

"Microsoft has made updates available to address the vulnerabilities. Install these updates as soon as possible," NCSC-NL noted. "Exchange Server 2016 and 2019 only receive security updates via the Extended Security Updates Program (ESU). Are you using one of these versions? If so, ensure that the server is accessible only internally and replace it if possible."

On Tuesday, threat security watchdog group Shadowserver said that it found 21,899 IP addresses with a Microsoft Exchange Server fingerprint that are still unpatched and exposed online, most of them in the United States (6,200) and Germany (5,100).

Unpatched Exchange servers exposed online (Shadowserver)

Germany's Federal Office for Information Security (BSI) also warned on Friday (as first spotted by Heise) that around 85% of all on-premises Exchange servers in Germany are still vulnerable to this vulnerability.

While CVE-2026-62911 has yet to be flagged as abused in the wild, Microsoft patched another Exchange Server vulnerability (CVE-2026-42897) in June that was exploited in cross-site scripting (XSS) attacks targeting Outlook Web Access users.

The Cybersecurity and Infrastructure Security Agency (CISA) also added the CVE-2026-42897 flaw to its Known Exploited Vulnerabilities Catalog on May 15 and ordered U.S. government agencies to patch their servers within two weeks.

Since November 2021, CISA has added 20 Microsoft Exchange Server vulnerabilities to its list of actively exploited security issues, 14 of them also flagged as abused in ransomware attacks.

In October, after Microsoft announced that Exchange 2016 and 2019 had reached the end of support, CISA and the National Security Agency (NSA) released joint guidance on hardening Exchange servers against attacks.

Two months ago, Microsoft also reminded customers that Exchange 2016 and Exchange 2019 security updates will stop shipping through the Extended Security Update (ESU) program in October 2026.

Update September 01, 08:58 EDT: Added BSI warning.

References in this story

  1. NVD - Home nvd.nist.gov
  2. Security Update Guide - Microsoft Security Response Center msrc.microsoft.com
  3. Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days www.bleepingcomputer.com Today is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities.
  4. Ernstige kwetsbaarheden in Microsoft Exchange Server | NCSC www.ncsc.nl Er zijn meerdere ernstige kwetsbaarheden gevonden in Microsoft Exchange Server. Een van deze kwetsbaarheden is CVE-2026-62911, met een CVSS-score van 8.0. Voor deze kwetsbaarheid is exploitcode online verschenen die…
  5. The Shadowserver Foundation (@shadowserver.bsky.social) bsky.app We are scanning & reporting daily on vulnerable Microsoft Exchange CVE-2026-62911 (Authentication Bypass by Capture-replay) instances in our Vulnerable Exchange reporting: https://www.shadowserver.org/what-we-do/network-…
  6. Time series · General statistics · The Shadowserver Foundation dashboard.shadowserver.org
  7. CERT-Bund (@[email protected]) social.bund.de 🚨 Für die kritische Schwachstelle CVE-2026-62911 in Microsoft Exchange wurde ein PoC-Exploit veröffentlicht, der die vollständige Übernahme von Systemen aus der Ferne ohne Authentifizierung ermöglicht. Der Hersteller…
  8. 85 percent of on-prem servers in Germany vulnerable www.heise.de A proof-of-concept exploit for a high-risk Exchange vulnerability is public. 85 percent of on-premises servers are vulnerable.
  9. Microsoft patches Exchange Server zero-day exploited in attacks www.bleepingcomputer.com Microsoft has patched an actively exploited Exchange Server vulnerability that allows threat actors to execute arbitrary JavaScript code in cross-site scripting (XSS) attacks targeting Outlook Web Access users.
  10. Security Update Guide - Microsoft Security Response Center msrc.microsoft.com
  11. CISA Adds One Known Exploited Vulnerability to Catalog | CISA www.cisa.gov CISA has added one new vulnerability to its KEV Catalog based on evidence of active exploitation.
  12. Known Exploited Vulnerabilities Catalog | CISA www.cisa.gov For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of…
  13. Known Exploited Vulnerabilities Catalog | CISA www.cisa.gov For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of…
  14. Microsoft: Exchange 2016 and 2019 reach end of support in 30 days www.bleepingcomputer.com ​Microsoft has reminded administrators again that Exchange 2016 and Exchange 2019 will reach the end of extended support next month and has provided guidance for decommissioning outdated servers.
  15. CISA and NSA share tips on securing Microsoft Exchange servers www.bleepingcomputer.com The Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) have released guidance to help IT administrators harden Microsoft Exchange servers on their networks against attacks.
  16. Microsoft to stop Exchange 2016 / 2019 security updates in October www.bleepingcomputer.com Microsoft has reminded customers that it will stop shipping security updates for Exchange 2016 and 2019 through the Extended Security Update (ESU) program in October.

Guides related to this story

← Back to all news