Nearly 22,000 internet-facing Microsoft Exchange servers remain unpatched against a high-severity vulnerability that could allow an attacker to take control of every mailbox on a compromised system.
Security researchers warn that the flaw, identified as CVE-2026-62911, affects Exchange Server 2016, Exchange Server 2019 and Exchange Server Subscription Edition. Microsoft issued a fix in its August 2026 security updates.
The Shadowserver Foundation said it had identified 21,899 IP addresses displaying an Exchange Server fingerprint and still exposed to the vulnerability. The largest concentrations were in the United States, with about 6,200 systems, and Germany, with roughly 5,100.
Exchange vulnerability could expose every mailbox
CVE-2026-62911 is an authentication-bypass flaw involving a capture-and-replay technique. Microsoft says an authorised attacker with basic access to a targeted server could exploit it remotely in a low-complexity attack, although user interaction is required.
In its security advisory, Microsoft said the flaw could enable an attacker to elevate privileges over a network and “take over the mailboxes of all Exchange users”. It added that a successful attacker could send and read emails and download attachments.
The Netherlands National Cyber Security Centre said recently that exploit code for the vulnerability was already available online, although Microsoft has not yet updated its advisory to confirm that assessment.
“Microsoft has made updates available to address the vulnerabilities. Install these updates as soon as possible,” the Dutch agency said.
It also warned that Exchange Server 2016 and 2019 receive security fixes only through Microsoft’s Extended Security Updates programme. Organisations using those versions were advised to ensure their servers were accessible only from internal networks and to replace them where possible.
Germany’s Federal Office for Information Security, known as the BSI, issued a separate warning after finding that about 85% of on-premises Exchange servers in the country remained vulnerable.
There is no public confirmation that CVE-2026-62911 has been exploited in attacks. However, its disclosure comes after another Exchange Server vulnerability was abused against users of Outlook Web Access.
Microsoft fixed that separate flaw, CVE-2026-42897, in June. It was used in cross-site scripting attacks, and the US Cybersecurity and Infrastructure Security Agency subsequently added it to its Known Exploited Vulnerabilities catalogue, ordering federal agencies to apply the fix within two weeks.
Since November 2021, CISA has listed 20 Exchange Server vulnerabilities as actively exploited. Fourteen of those have also been linked to ransomware attacks.
Microsoft has previously said that Exchange Server 2016 and 2019 have reached the end of their standard support periods. Security updates provided through the Extended Security Updates programme are due to stop in October 2026, increasing pressure on organisations that have not migrated or upgraded.
