Nearly 22,000 Microsoft Exchange Servers at Risk of Hijack Attacks as Patch Remains Unapplied
A staggering number of Microsoft Exchange servers remain unpatched against a critical security flaw that allows attackers to hijack user mailboxes. According to recent findings by Shadowserver, a threat intelligence watchdog group, nearly 22,000 Exchange servers are still vulnerable to the high-severity authentication bypass vulnerability, tracked as CVE-2026-62911.
This security issue affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) software. Attackers with basic privileges on the targeted server can exploit this flaw in low-complexity attacks that require user interaction. Once compromised, attackers can send emails, read emails, and download attachments from all affected users’ mailboxes.
Microsoft patched the CVE-2026-62911 vulnerability during its August 2026 Patch Tuesday update. However, it appears that many organizations have yet to apply the necessary fixes. The Netherlands National Cyber Security Centre (NCSC-NL) has warned that exploit code for this vulnerability is already available online. “Microsoft has made updates available to address the vulnerabilities,” NCSC-NL noted. “Install these updates as soon as possible.”
The severity of the situation is highlighted by the fact that 21,899 IP addresses with a Microsoft Exchange Server fingerprint were found to be still unpatched and exposed online, primarily in the United States (6,200) and Germany (5,100). Germany’s Federal Office for Information Security (BSI) has also warned that around 85% of all on-premises Exchange servers in Germany are still vulnerable to this vulnerability.
This is not an isolated incident. In June, Microsoft patched another Exchange Server vulnerability (CVE-2026-42897), which was exploited in cross-site scripting (XSS) attacks targeting Outlook Web Access users. The Cybersecurity and Infrastructure Security Agency (CISA) has added several Microsoft Exchange Server vulnerabilities to its list of actively exploited security issues, including 14 flagged as abused in ransomware attacks.
The takeaway from this story is clear: unpatched servers are a ticking time bomb for any organization. As we’ve seen with previous examples, attackers can exploit these vulnerabilities to gain unauthorized access and wreak havoc on compromised systems. To avoid falling victim to such attacks, it’s essential that organizations prioritize patching their Exchange servers as soon as possible.
In the meantime, Microsoft is continuing to push updates to address these security issues. Organizations should take this opportunity to review their patch management processes and ensure that all critical software, including Exchange Server, is up-to-date with the latest security patches. By doing so, they can significantly reduce the risk of falling victim to hijack attacks and protect their users’ sensitive information from potential exploitation.
Source: Bleeping Computer — 2026-09-01