Thousands of Microsoft Exchange Servers Still Vulnerable to Major Security Flaw

More than 21,800 Microsoft Exchange servers globally remain unpatched against CVE-2026-62911, a severe authentication bypass vulnerability that enables attackers to capture and replay authentication traffic, potentially gaining full control over enterprise email infrastructures. This figure, verified from daily internet-wide scans conducted by the Shadowserver Foundation, highlights how many organizations have yet to address one of the most critical vulnerabilities disclosed in 2026.

First made public on August 11, 2026, CVE-2026-62911 is classified as an authentication-capture replay flaw (CWE-294) with a CVSS severity score of 8.0. The vulnerability arises from exposed MRSProxy endpoints in Exchange servers that fail to enforce Extended Protection for Authentication. This lapse allows attackers to relay NTLM credentials using the machine account tied to the server, effectively bypassing standard authentication procedures and opening the door to mailbox compromises.

Which Servers Are at Risk?

Products that are vulnerable include Microsoft Exchange Server 2016 Cumulative Update 23, Exchange Server 2019 Cumulative Updates 14 and 15, and the Exchange Server Subscription Edition RTM baseline. Microsoft has issued patches for each version—builds 15.1.2507.72, 15.2.1544.44, 15.2.1748.49, and 15.2.2562.46—through its August 2026 security updates.

The Shadowserver scans reveal that the United States has the highest number of exposed systems—approximately 6,200—followed by Germany with about 5,100. Several hundred vulnerable servers also persist in the UK, Russia, Canada, Austria, and France, with smaller clusters scattered across Italy, the Netherlands, China, and multiple other countries.

What to Do Now

Security teams operating on-premises Exchange environments need to confirm not just the cumulative update level but the exact build number, since pre-August 2026 builds are still exploitable. Applying the August security patches, restarting affected services, enforcing TLS 1.2 or higher, and tightening monitoring of NTLM relay activity are the recommended mitigation steps.

The urgency escalated after proof-of-concept exploit code emerged around this time. For systems still unpatched, the period during which attackers are quietly scanning for vulnerable targets is rapidly shrinking—and the risk of active attacks rising sharply.

This vulnerability was first demonstrated at Pwn2Own Berlin 2026 by Trend Micro’s Zero Day Initiative, which has since disputed Microsoft’s assessment of exploit maturity. That adds further gravity to the situation, given the ongoing real-world proof of potential attack chains that go far beyond initial access.

Despite Microsoft’s fixes, the persistence of tens of thousands of exposed servers underscores the challenges many organizations face in applying security updates promptly—whether due to complexity of environments, testing concerns, or awareness gaps.

Why this matters: Exchange servers often serve as central hubs for corporate communication and data. In large organizations, a single compromised mailbox or administrative account can cascade into far-reaching breaches.

An eye on the future: Watch for threat actors to move from scanning to active exploitation quickly. Organizations should validate not just update levels but patch build numbers. CERTs and security operations centers should leverage available visibility tools—such as Shadowserver’s daily reports—to stay ahead of emergent attacks.