22k Unpatched Exchange Servers Vulnerable to Hijack Attacks
Nearly 22,000 Microsoft Exchange servers are still vulnerable to hijack attacks due to an unpatched authentication bypass vulnerability.
The security flaw, tracked as CVE-2026-62911, affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) software.
Microsoft patched the vulnerability during the August 2026 Patch Tuesday, but many servers remain unpatched. The Netherlands National Cyber Security Centre (NCSC-NL) reported last week that exploit code for this vulnerability is already available online.
Shadowserver found 21,899 IP addresses with a Microsoft Exchange Server fingerprint that are still unpatched and exposed online, most of them in the United States (6,200) and Germany (5,100).