Vulnerability Threatens Thousands of Unpatched Exchange Servers
A critical vulnerability has been discovered in Microsoft's Exchange Server 2016 and Exchange Server Subscription Edition, allowing hackers to gain full access to affected systems. The flaw, designated CVE-2026-62911, was recently identified by researchers.
Microsoft released security patches as part of its August 2026 Patch Tuesday release to address the issue. However, despite this effort, there are still 21,899 unpatched servers at risk, according to The Shadowserver Foundation.
The highest concentrations of vulnerable servers are in the US and Germany, with the Netherlands National Cyber Security Centre and other agencies urging admins to install the latest patches as soon as possible.