Skip to content
Back to Guavy Wire
Stocks

Microsoft Exchange Vulnerability Patched, But Thousands of Servers Remain Unpatched

Instruments
MSFT
Share

A high-severity authentication bypass vulnerability in Microsoft Exchange Server has been patched by Microsoft as part of its August 2026 Patch Tuesday update. The vulnerability, known as CVE-2026-62911, affects Exchange Server 2016, 2019, and Subscription Edition, and allows an attacker with basic privileges to take over all mailboxes on the targeted server.

According to threat intelligence group Shadowserver, around 22,000 Exchange servers remain unpatched and exposed to the internet, including roughly 6,200 in the United States and 5,100 in Germany. The Netherlands National Cyber Security Centre (NCSC-NL) has confirmed that working exploit code is already publicly available.

Microsoft recommends applying the patch as a priority for on-premises Exchange servers. For older versions of Exchange, such as those on the Extended Security Update (ESU) program, it's essential to confirm enrollment and apply the update before ESU ends in October 2026.

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc