Skip to content
Back to Guavy Wire
Stocks

22k Unpatched Exchange Servers Vulnerable to Hijack Attacks

Instruments
MSFT
Share

Nearly 22,000 Microsoft Exchange servers are still vulnerable to hijack attacks due to an unpatched authentication bypass vulnerability.

The security flaw, tracked as CVE-2026-62911, affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) software.

Microsoft patched the vulnerability during the August 2026 Patch Tuesday, but many servers remain unpatched. The Netherlands National Cyber Security Centre (NCSC-NL) reported last week that exploit code for this vulnerability is already available online.

Shadowserver found 21,899 IP addresses with a Microsoft Exchange Server fingerprint that are still unpatched and exposed online, most of them in the United States (6,200) and Germany (5,100).

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc