Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Fake Coding Tests Impersonate Recruiters to Infect Software Developers
September 1, 2026
Critical Langflow RCE (CVE-2024-34200) Actively Exploited by Attackers
September 1, 2026
Five Hackers Plead Guilty to ATM Jackpotting Attacks
September 1, 2026
Home/CyberSecurity News/21,000+ Microsoft Exchange Servers Exposed to Critical CVE-2026-62911 Exploits
CyberSecurity News

21,000+ Microsoft Exchange Servers Exposed to Critical CVE-2026-62911 Exploits

Key Takeaways Over 21,000 Microsoft Exchange servers globally remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability. This flaw, with a CVSS score of 8.0, allows...

Sarah simpson
Sarah simpson
September 1, 2026 3 Min Read
2 0

Key Takeaways

  • Over 21,000 Microsoft Exchange servers globally remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability.
  • This flaw, with a CVSS score of 8.0, allows attackers to relay NTLM credentials and gain full control over affected Exchange environments.
  • The vulnerability impacts Exchange Server 2016 CU23, Exchange Server 2019 CU14 and CU15, and Exchange Server Subscription Edition RTM.
  • Patches were released by Microsoft in August 2026, but adoption rates are concerningly low, leaving many organizations exposed.

Thousands of Microsoft Exchange Servers Remain Vulnerable to Critical Authentication Bypass

More than 21,000 Microsoft Exchange servers worldwide are currently operating without the necessary security updates to address CVE-2026-62911, a severe authentication bypass vulnerability. This critical flaw could allow malicious actors to completely compromise enterprise email infrastructure, according to recent cybersecurity reports.

Table Of Content

  • Key Takeaways
  • Thousands of Microsoft Exchange Servers Remain Vulnerable to Critical Authentication Bypass
  • Understanding CVE-2026-62911
  • Affected Versions and Patches
  • Global Exposure Insights
  • What You Should Do

Daily scans conducted by the Shadowserver Foundation reveal that as of August 31, 2026, precisely 21,899 unique IP addresses host vulnerable Exchange instances. This figure highlights a significant delay in organizations applying patches for one of the most impactful disclosures from this year’s Patch Tuesday.

Understanding CVE-2026-62911

CVE-2026-62911 is categorized as an authentication bypass vulnerability through a capture-replay attack, tracked under CWE-294, and has been assigned a CVSS score of 8.0. Microsoft initially released details about this issue on August 11, 2026, describing it as an elevation-of-privilege flaw. The vendor’s assessment indicated that an attacker could capture and replay authentication traffic to impersonate legitimate users and escalate privileges within an Exchange Server environment.

However, security researchers have since demonstrated that the vulnerability can be leveraged for a much more severe attack. The flaw reportedly originates from an internet-accessible MRSProxy endpoint that fails to enforce Extended Protection for Authentication. This oversight enables attackers to relay NTLM credentials from an Exchange machine account, effectively bypassing authentication entirely and paving the way for a full mailbox compromise.

The vulnerability was first publicly showcased at Pwn2Own Berlin 2026 by Trend Micro’s Zero Day Initiative, which subsequently challenged Microsoft’s “unproven” exploit-maturity rating, suggesting the risk was higher than initially assessed.

Affected Versions and Patches

The vulnerability affects several versions of Microsoft Exchange Server, specifically:

  • Exchange Server 2016 Cumulative Update 23
  • Exchange Server 2019 Cumulative Update 14
  • Exchange Server 2019 Cumulative Update 15
  • Exchange Server Subscription Edition RTM

Microsoft released corresponding fixes in the August 2026 security updates. The patched builds are:

  • Exchange 2016 CU23: Build 15.1.2507.72
  • Exchange 2019 CU14: Build 15.2.1544.44
  • Exchange 2019 CU15: Build 15.2.1748.49
  • Subscription Edition: Build 15.2.2562.46
Exchange Server Version Vulnerable Cumulative Update Patched Build (August 2026)
Exchange Server 2016 Cumulative Update 23 Build 15.1.2507.72
Exchange Server 2019 Cumulative Update 14 Build 15.2.1544.44
Exchange Server 2019 Cumulative Update 15 Build 15.2.1748.49
Exchange Server Subscription Edition RTM Baseline Build 15.2.2562.46

Global Exposure Insights

According to Shadowserver Foundation’s scan reports, which include daily IPv4 full-internet sweeps and IPv6 hitlist scans, the United States accounts for the largest number of exposed instances, with approximately 6,200 vulnerable servers. Germany follows with about 5,100 unpatched systems. The United Kingdom, Russia, Canada, Austria, and France each report several hundred exposed servers, with smaller concentrations observed in Italy, the Netherlands, China, and numerous other countries.

Shadowserver has committed to providing daily updates on these vulnerable instances through its Vulnerable Exchange Server Report, offering network defenders and national CERTs continuous insight into the status of unpatched systems within their respective jurisdictions.

What You Should Do

  • Verify Build Numbers: Organizations operating on-premises Exchange servers must verify their exact build numbers. Do not assume that merely applying a cumulative update ensures protection, as sub-versions released prior to the August 2026 security update remain exploitable.
  • Apply Patches Immediately: Implement the relevant Knowledge Base (KB) updates for CVE-2026-62911 without delay. This involves applying the specific patched builds (e.g., 15.1.2507.72 for Exchange 2016 CU23).
  • Restart Services: After applying patches, ensure all affected Exchange services are properly restarted to finalize the update process.
  • Enforce Strong Authentication: Strengthen authentication controls by enforcing TLS 1.2 or higher.
  • Monitor for Anomalous Activity: Implement continuous monitoring for unusual NTLM relay activity, which could indicate attempted exploitation of this vulnerability.
  • Review Network Segmentation: Evaluate and enhance network segmentation to limit the blast radius in case of a successful exploit.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Fake ChatGPT Sites Deliver Malware via Malvertising Campaign

Next Post

Critical JFrog Artifactory Auth Bypass CVE-2023-46233 Lets Attackers Gain Admin Access

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Microsoft Teams Vulnerability Lets Attackers Impersonate Users
September 1, 2026
Critical JFrog Artifactory Auth Bypass CVE-2023-46233 Lets Attackers Gain Admin Access
September 1, 2026
21,000+ Microsoft Exchange Servers Exposed to Critical CVE-2026-62911 Exploits
September 1, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us