Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

A staggering 22,000 Microsoft Exchange servers remain unpatched and vulnerable to hijack attacks, leaving users’ email accounts at risk of being taken over by attackers. The security flaw, tracked as CVE-2026-62911, affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) software, allowing authorized attackers to elevate privileges and gain control over all user mailboxes.

Microsoft had patched this vulnerability in August, but it appears that many organizations have yet to apply the necessary updates. The Netherlands National Cyber Security Centre (NCSC-NL) recently warned that exploit code for CVE-2026-62911 is already available online, making it a matter of when, not if, attackers will start exploiting this vulnerability.

The consequences of a successful attack are severe: attackers can send emails, read emails, download attachments, and even take over the entire Exchange server. This vulnerability is particularly concerning because it requires only basic privileges on the targeted server to exploit, and user interaction is needed in low-complexity attacks. The fact that many organizations have yet to patch their servers is alarming, given the ease with which attackers can gain access.

The numbers are eye-opening: Shadowserver, a threat security watchdog group, found 21,899 IP addresses with a Microsoft Exchange Server fingerprint that are still unpatched and exposed online. Most of these vulnerable servers are located in the United States (6,200) and Germany (5,100). In fact, Germany’s Federal Office for Information Security (BSI) warned that around 85% of all on-premises Exchange servers in Germany are still vulnerable to this vulnerability.

This is not an isolated incident: Microsoft had previously patched another Exchange Server vulnerability, CVE-2026-42897, which was exploited in cross-site scripting (XSS) attacks targeting Outlook Web Access users. The Cybersecurity and Infrastructure Security Agency (CISA) added this flaw to its Known Exploited Vulnerabilities Catalog on May 15, ordering U.S. government agencies to patch their servers within two weeks.

Given the history of Microsoft Exchange Server vulnerabilities being exploited in the wild, it’s essential for organizations to take immediate action to protect themselves. This includes applying the necessary updates, hardening Exchange servers against attacks, and regularly monitoring for signs of suspicious activity.

In light of this vulnerability, we recommend that organizations using Microsoft Exchange Server 2016 or 2019 take the following steps: install the latest security updates as soon as possible, ensure that the server is accessible only internally, and consider replacing it with a newer version if possible. By taking these precautions, organizations can minimize their risk of being compromised by attackers exploiting CVE-2026-62911.


Source: Bleeping Computer — 2026-09-01