21,000+ Microsoft Exchange Servers Remain Exposed to Active CVE-2026-62911 Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Nearly 22,000 Microsoft Exchange servers worldwide are still running unpatched for CVE-2026-62911, a critical authentication-bypass vulnerability that attackers can exploit to seize control of enterprise email infrastructure.

According to daily internet-wide scans published by the Shadowserver Foundation, exactly 21,899 unique IP addresses were flagged as vulnerable as of August 31, 2026, underscoring how slowly organizations are responding to one of this year’s most consequential Patch Tuesday disclosures.

CVE-2026-62911 Microsoft Exchange

CVE-2026-62911 is classified as an authentication bypass by capture-replay flaw, tracked under CWE-294, and carries a CVSS score of 8.0.

Microsoft disclosed the issue on August 11, 2026, describing it as an elevation-of-privilege vulnerability that lets an attacker who can capture and replay authentication traffic impersonate legitimate users and escalate privileges across Exchange Server.

Security researchers have since shown the bug can be chained into a far more dangerous scenario.

Reports indicate the flaw stems from an internet-reachable MRSProxy endpoint that fails to enforce Extended Protection for Authentication, allowing attackers to relay NTLM credentials from an Exchange machine account and effectively bypass authentication entirely, opening a path toward full mailbox compromise.

The vulnerability was originally demonstrated at Pwn2Own Berlin 2026 by Trend Micro’s Zero Day Initiative, which has publicly disputed Microsoft’s “unproven” exploit-maturity rating.

Affected products include Exchange Server 2016 Cumulative Update 23, Exchange Server 2019 CU14 and CU15, and Exchange Server Subscription Edition RTM.

Microsoft has released fixed builds for each: 15.1.2507.72 for Exchange 2016 CU23, 15.2.1544.44 for 2019 CU14, 15.2.1748.49 for 2019 CU15, and 15.2.2562.46 for Subscription Edition, delivered through the August 2026 security updates.

Exchange Server Version Vulnerable Cumulative Update Patched Build (August 2026)
Exchange Server 2016 Cumulative Update 23 Build 15.1.2507.72
Exchange Server 2019 Cumulative Update 14 Build 15.2.1544.44
Exchange Server 2019 Cumulative Update 15 Build 15.2.1748.49
Exchange Server Subscription Edition RTM Baseline Build 15.2.2562.46

As detailed in Shadowserver Foundation’s scan reports, scanning data drawn from daily IPv4 full-internet sweeps and IPv6 hitlist scans shows the United States leading exposure with roughly 6,200 vulnerable instances, followed by Germany at about 5,100.

The United Kingdom, Russia, Canada, Austria, and France each report several hundred additional exposed servers, with smaller clusters visible across Italy, the Netherlands, China, and dozens of other countries.

Shadowserver has stated it is now reporting on these vulnerable instances daily through its Vulnerable Exchange Server Report, giving network defenders and national CERTs continuous visibility into unpatched systems within their jurisdictions.

Security teams running on-premises Exchange should verify their exact build number rather than assuming a cumulative update alone provides protection, since sub-versions before the August 2026 security update remain exploitable.

Immediate remediation involves applying the relevant KB update, restarting affected services, and enforcing stronger authentication controls such as TLS 1.2 or higher alongside monitoring for anomalous NTLM relay activity.

Given the public proof-of-concept exploit code that surfaced around this reporting period, organizations that have not yet patched face a rapidly narrowing window before opportunistic scanning turns into active exploitation.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post 21,000+ Microsoft Exchange Servers Remain Exposed to Active CVE-2026-62911 Exploitation appeared first on Cyber Security News.