22,000 Exchange Servers Exposed to Mailbox-Hijack Flaw
Corporate email can fall into an attacker’s hands after the compromise of a single low-privilege account. Nearly 22,000 internet-facing Microsoft Exchange servers have not received the fix for CVE-2026-62911, a flaw that allows every employee’s mailbox to be seized.
An Authentication Bypass by Capture-Replay
Microsoft rated the vulnerability 8.0 out of 10 on the CVSS 3.1 scale and classified it as an authentication bypass by capture-replay. In such an attack, a previously intercepted request is sent to the server again, and the system accepts it as legitimate. After elevating privileges, the attacker can read messages, download attachments, and send emails on behalf of users.
Microsoft’s official assessment assumes basic privileges and some user action. However, the Zero Day Initiative describes a separate authentication bypass that needs neither an account nor victim participation. DEVCORE researcher Orange Tsai discovered the flaw, and the fix was released on 11 August 2026.
Nearly 22,000 Exposed Servers
Shadowserver found 21,899 IP addresses showing signs of unprotected Exchange servers. The greatest number were in the United States, where about 6,200 addresses were counted, and Germany, with 5,100. Germany’s BSI agency estimated that roughly 85% of on-premises Exchange servers in the country remain vulnerable.
The problem affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition. The Netherlands’ National Cyber Security Centre warned that exploit code has already appeared publicly. At the time of publication, there was no confirmation of real-world attacks.
Patching and Mitigation Guidance
Administrators should install the August security updates or newer versions, verify the builds of all externally accessible servers, and review login and mail-operation logs. Exchange 2016 and 2019 receive fixes only through the Extended Security Updates program. Therefore, older systems should be closed off from the internet and replaced with Exchange Server Subscription Edition.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.