Microsoft Exchange Vulnerability Patched, But Thousands of Servers Remain Unpatched
A high-severity authentication bypass vulnerability in Microsoft Exchange Server has been patched by Microsoft as part of its August 2026 Patch Tuesday update. The vulnerability, known as CVE-2026-62911, affects Exchange Server 2016, 2019, and Subscription Edition, and allows an attacker with basic privileges to take over all mailboxes on the targeted server.
According to threat intelligence group Shadowserver, around 22,000 Exchange servers remain unpatched and exposed to the internet, including roughly 6,200 in the United States and 5,100 in Germany. The Netherlands National Cyber Security Centre (NCSC-NL) has confirmed that working exploit code is already publicly available.
Microsoft recommends applying the patch as a priority for on-premises Exchange servers. For older versions of Exchange, such as those on the Extended Security Update (ESU) program, it's essential to confirm enrollment and apply the update before ESU ends in October 2026.