21,000+ Microsoft Exchange Servers Exposed to Critical CVE-2026-62911 Exploits
Key Takeaways Over 21,000 Microsoft Exchange servers globally remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability. This flaw, with a CVSS score of 8.0, allows...
Key Takeaways
- Over 21,000 Microsoft Exchange servers globally remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability.
- This flaw, with a CVSS score of 8.0, allows attackers to relay NTLM credentials and gain full control over affected Exchange environments.
- The vulnerability impacts Exchange Server 2016 CU23, Exchange Server 2019 CU14 and CU15, and Exchange Server Subscription Edition RTM.
- Patches were released by Microsoft in August 2026, but adoption rates are concerningly low, leaving many organizations exposed.
Thousands of Microsoft Exchange Servers Remain Vulnerable to Critical Authentication Bypass
More than 21,000 Microsoft Exchange servers worldwide are currently operating without the necessary security updates to address CVE-2026-62911, a severe authentication bypass vulnerability. This critical flaw could allow malicious actors to completely compromise enterprise email infrastructure, according to recent cybersecurity reports.
Table Of Content
Daily scans conducted by the Shadowserver Foundation reveal that as of August 31, 2026, precisely 21,899 unique IP addresses host vulnerable Exchange instances. This figure highlights a significant delay in organizations applying patches for one of the most impactful disclosures from this year’s Patch Tuesday.
Understanding CVE-2026-62911
CVE-2026-62911 is categorized as an authentication bypass vulnerability through a capture-replay attack, tracked under CWE-294, and has been assigned a CVSS score of 8.0. Microsoft initially released details about this issue on August 11, 2026, describing it as an elevation-of-privilege flaw. The vendor’s assessment indicated that an attacker could capture and replay authentication traffic to impersonate legitimate users and escalate privileges within an Exchange Server environment.
However, security researchers have since demonstrated that the vulnerability can be leveraged for a much more severe attack. The flaw reportedly originates from an internet-accessible MRSProxy endpoint that fails to enforce Extended Protection for Authentication. This oversight enables attackers to relay NTLM credentials from an Exchange machine account, effectively bypassing authentication entirely and paving the way for a full mailbox compromise.
The vulnerability was first publicly showcased at Pwn2Own Berlin 2026 by Trend Micro’s Zero Day Initiative, which subsequently challenged Microsoft’s “unproven” exploit-maturity rating, suggesting the risk was higher than initially assessed.
Affected Versions and Patches
The vulnerability affects several versions of Microsoft Exchange Server, specifically:
- Exchange Server 2016 Cumulative Update 23
- Exchange Server 2019 Cumulative Update 14
- Exchange Server 2019 Cumulative Update 15
- Exchange Server Subscription Edition RTM
Microsoft released corresponding fixes in the August 2026 security updates. The patched builds are:
- Exchange 2016 CU23: Build 15.1.2507.72
- Exchange 2019 CU14: Build 15.2.1544.44
- Exchange 2019 CU15: Build 15.2.1748.49
- Subscription Edition: Build 15.2.2562.46
| Exchange Server Version | Vulnerable Cumulative Update | Patched Build (August 2026) |
| Exchange Server 2016 | Cumulative Update 23 | Build 15.1.2507.72 |
| Exchange Server 2019 | Cumulative Update 14 | Build 15.2.1544.44 |
| Exchange Server 2019 | Cumulative Update 15 | Build 15.2.1748.49 |
| Exchange Server Subscription Edition | RTM Baseline | Build 15.2.2562.46 |
Global Exposure Insights
According to Shadowserver Foundation’s scan reports, which include daily IPv4 full-internet sweeps and IPv6 hitlist scans, the United States accounts for the largest number of exposed instances, with approximately 6,200 vulnerable servers. Germany follows with about 5,100 unpatched systems. The United Kingdom, Russia, Canada, Austria, and France each report several hundred exposed servers, with smaller concentrations observed in Italy, the Netherlands, China, and numerous other countries.
Shadowserver has committed to providing daily updates on these vulnerable instances through its Vulnerable Exchange Server Report, offering network defenders and national CERTs continuous insight into the status of unpatched systems within their respective jurisdictions.
What You Should Do
- Verify Build Numbers: Organizations operating on-premises Exchange servers must verify their exact build numbers. Do not assume that merely applying a cumulative update ensures protection, as sub-versions released prior to the August 2026 security update remain exploitable.
- Apply Patches Immediately: Implement the relevant Knowledge Base (KB) updates for CVE-2026-62911 without delay. This involves applying the specific patched builds (e.g., 15.1.2507.72 for Exchange 2016 CU23).
- Restart Services: After applying patches, ensure all affected Exchange services are properly restarted to finalize the update process.
- Enforce Strong Authentication: Strengthen authentication controls by enforcing TLS 1.2 or higher.
- Monitor for Anomalous Activity: Implement continuous monitoring for unusual NTLM relay activity, which could indicate attempted exploitation of this vulnerability.
- Review Network Segmentation: Evaluate and enhance network segmentation to limit the blast radius in case of a successful exploit.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.