Microsoft Exchange Servers Left Exposed to Critical Vulnerability
A critical vulnerability in Microsoft Exchange Server has left nearly 22,000 internet-facing systems potentially exposed to attacks. The flaw, tracked as CVE-2026-62911, affects on-premises installations of Exchange Server 2016, 2019, and Subscription Edition.
Despite the availability of patches released by Microsoft on August 11, many servers remain vulnerable. In fact, internet-scanning data published at the end of August indicates that a substantial number of Exchange installations still need to be patched.
The vulnerability allows an attacker to take over Exchange mailboxes, read private messages, download attachments, and send email while impersonating legitimate users.
Security researcher Orange Tsai discovered the flaw and reported it to Microsoft. The company classifies CVE-2026-62911 as an elevation-of-privilege vulnerability caused by an authentication bypass through capture-and-replay techniques.