Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. Tracked as CVE-2026-62911 and reported by DEVCORE Research Team's Orange Tsai, this security flaw affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) software. Threat actors with basic privileges on the targeted server can exploit it in low-complexity attacks that require user interaction. "Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network," Microsoft said when it patched the vulnerability during the August 2026 Patch Tuesday. "The attacker would be able to take over the mailboxes of all Exchange users, attackers can send emails, read emails, download attachments." While Microsoft has yet to update the CVE-2026-62911 advisory to confirm it, the Netherlands National Cyber Security Centre (NCSC-NL) reported last week that exploit code for this vulnerability is already available online. "Microsoft has made updates available to address the vulnerabilities. Install these updates as soon as possible," NCSC-NL noted. "Exchange Server 2016 and 2019 only receive security updates via the Extended Security Updates Program (ESU). Are you using one of these versions? If so, ensure that the server is accessible only internally and replace it if possible." On Tuesday, threat sec...
Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
Affected Software
Frequently Asked Questions
Which Exchange deployments are affected by CVE-2026-62911?
The vulnerability affects Microsoft Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE). The article says nearly 22,000 exposed online Exchange servers remain unpatched.
What could an attacker do by exploiting this vulnerability?
An authorized attacker with basic privileges on the targeted server could elevate privileges over the network and take over all Exchange user mailboxes. This could allow them to send and read email and download attachments.
Is exploitation of CVE-2026-62911 confirmed?
The article says the Netherlands National Cyber Security Centre reported that exploit code is available online, while Microsoft had not yet updated its advisory to confirm this. The vulnerability is also flagged as exploited and was KEV-listed on September 1, 2026.
What mitigation does the article indicate?
Microsoft released updates for the vulnerability during the August 2026 Patch Tuesday. The Netherlands National Cyber Security Centre urged organizations to install the available updates.