A high-severity authentication bypass vulnerability (CVE-2026-62911) has left thousands of Microsoft Exchange servers exposed, allowing attackers to hijack all user mailboxes. Despite available patches, thousands of organizations globally remain at risk.
- Approximately 21,899 Microsoft Exchange servers remain unpatched and exposed online.
- The CVE-2026-62911 flaw allows attackers to hijack mailboxes, read emails, and download attachments.
- The United States and Germany are the most affected regions.
- Exploit code is reportedly available online, increasing the risk of active attacks.
In a concerning revelation for global cybersecurity, nearly 22,000 Microsoft Exchange servers have been found exposed to a high-severity authentication bypass vulnerability. Tracked as CVE-2026-62911, this security flaw allows threat actors with basic privileges to elevate their access and effectively hijack every single user mailbox on a targeted server.
The vulnerability affects a wide range of software, including Exchange Server 2016, Exchange Server 2019, and the Exchange Server Subscription Edition (SE). According to Microsoft, the flaw stems from a capture-replay mechanism that allows an authorized attacker to elevate privileges over a network, granting them the power to send emails, read sensitive correspondence, and download attachments without authorization.
Why This Matters
BozokMedia analysis shows that the persistence of this vulnerability highlights a systemic failure in patch management across enterprise environments. While Microsoft released a fix during the August 2026 Patch Tuesday, the lag in deployment creates a massive window of opportunity for ransomware gangs and state-sponsored actors. The fact that exploit code is already circulating online transforms this from a theoretical risk into an imminent threat.
The window between patch release and deployment is the 'Golden Hour' for hackers; 22,000 exposed servers represent an open invitation for global espionage.
Data provided by the watchdog group Shadowserver indicates that the United States (6,200 servers) and Germany (5,100 servers) are the hardest hit. In Germany, the Federal Office for Information Security (BSI) warned that a staggering 85% of all on-premises Exchange servers remain vulnerable, showcasing a critical lack of urgency in updating legacy infrastructure.
This incident is not an isolated case. The Cybersecurity and Infrastructure Security Agency (CISA) has a long history of tracking Exchange vulnerabilities, having added 20 such flaws to its Known Exploited Vulnerabilities Catalog since 2021, many of which were leveraged in devastating ransomware attacks.
Furthermore, the urgency is compounded by the end-of-support timeline. Microsoft has previously announced that security updates for Exchange 2016 and 2019 will cease entirely through the Extended Security Update (ESU) program in October 2026, leaving organizations that fail to migrate now in a precarious position.
| Metric | CVE-2026-62911 (Current) | CVE-2026-42897 (Previous) |
|---|---|---|
| Primary Risk | Full Mailbox Hijack | Cross-Site Scripting (XSS) |
| Severity | High/Critical | High |
| Impact | Privilege Escalation | User Session Theft |
Frequently Asked Questions
Q1: Which versions of Microsoft Exchange are affected by CVE-2026-62911?
A: The vulnerability affects Exchange Server 2016, Exchange Server 2019, and the Exchange Server Subscription Edition (SE).
Q2: How can organizations protect themselves if they cannot patch immediately?
A: The NCSC-NL recommends ensuring that the server is accessible only internally and replacing the legacy version as soon as possible.