A security update has been available for weeks, but nearly 22,000 internet-facing Microsoft Exchange servers still appear vulnerable to a serious flaw that could put entire corporate mail systems at risk.
The vulnerability, tracked as CVE-2026-62911, affects supported Exchange Server Subscription Edition installations as well as Exchange Server 2016 and 2019 systems receiving Extended Security Updates. Microsoft addressed the issue in its August 2026 security releases.
The situation has become more urgent since then. The Netherlands’ National Cyber Security Centre (NCSC-NL) said on August 28 that proof-of-concept code for the vulnerability had appeared online and raised its assessment of the issue to High/High.
Meanwhile, internet scanning by the Shadowserver Foundation indicates that a large number of vulnerable systems remain reachable from the public internet. Reports based on its latest scans put that number at 21,899 unique IP addresses, with the largest concentrations found in the United States and Germany.

What is CVE-2026-62911?
CVE-2026-62911 is a vulnerability affecting on-premises Microsoft Exchange Server.
Microsoft rates the issue as high severity, while the updated NCSC-NL advisory gives it a CVSS v3 score of 8.0. The weakness involves authentication bypass behavior and can ultimately expose far more than a single account.
In practical terms, successful exploitation can give an attacker access to Exchange mailboxes, potentially exposing email messages and attachments and creating an opportunity for further attacks inside an organization’s network.
That makes Exchange an especially valuable target.
Corporate email systems contain far more than routine messages. They can hold password-reset emails, invoices, internal documents, customer information and conversations that reveal how an organization operates.
Compromising the mail server can therefore become the beginning of a much larger intrusion.
An exposed Exchange server isn’t just an email problem. It can become an entry point into the rest of an organization’s network.
The vulnerability has roots in Pwn2Own Berlin
The flaw did not emerge without warning.
Security researcher Orange Tsai of DEVCORE demonstrated an Exchange exploit chain at Pwn2Own Berlin 2026 in May. The successful attempt achieved remote code execution as SYSTEM on Microsoft Exchange and earned $200,000 at the competition.
The Zero Day Initiative later published details for CVE-2026-62911 as part of the coordinated disclosure process.
ZDI describes the underlying issue as involving improper validation of a user-controlled file path. Its advisory notes that although authentication is normally required, the authentication mechanism can be bypassed. Successful exploitation can result in arbitrary code execution with SYSTEM privileges.
Microsoft released the corresponding security update on August 11, 2026.
That should have started the clock for organizations running Exchange on their own infrastructure.
For thousands of servers, however, the clock is still running.
Why 22,000 exposed servers matter
The raw number is concerning, but the circumstances surrounding it are arguably more important.
Shadowserver performs continuous internet-wide scanning for vulnerable systems and added CVE-2026-62911 detection to its Exchange reporting on August 27. Its Exchange scans assess exposed systems using observable version information.
By the end of August, reports drawing on those scans identified 21,899 internet-accessible Exchange instances that appeared not to have received the required update.
Roughly 6,200 were located in the United States, while approximately 5,100 were in Germany.
Those numbers can change as systems are patched, taken offline or newly detected, so they should be treated as a snapshot rather than a permanent count.
But even as a snapshot, nearly 22,000 exposed servers represents a substantial attack surface.
And the publication of proof-of-concept code changes the risk equation.
Public proof-of-concept code increases the urgency
A vulnerability being publicly documented does not automatically mean widespread attacks are underway.
There is an important distinction between a working proof of concept being available and confirmed exploitation in the wild.
As of September 1, Microsoft has not publicly classified CVE-2026-62911 as being exploited in widespread real-world attacks.
NCSC-NL has, however, confirmed that proof-of-concept exploit code is publicly available and says it can lower the barrier to carrying out an attack. The agency consequently increased its risk assessment and urged organizations to install Microsoft’s updates as quickly as possible.
That distinction matters.
Saying that thousands of Exchange servers are already being compromised would go beyond the available evidence. Saying that attackers now have more information with which to target thousands of still-unpatched systems accurately describes why defenders have less room to delay.
Public exploit code doesn’t prove that mass exploitation has begun — but it makes leaving an internet-facing server unpatched increasingly difficult to justify.

Exchange 2016 and 2019 face another problem
The vulnerability also highlights a broader issue for organizations still operating older Exchange installations.
Microsoft says Exchange Server 2016 and Exchange Server 2019 are already out of normal support. Security updates released between May and October 2026 are available to those versions only for organizations enrolled in Microsoft’s Period 2 Extended Security Update program.
NCSC-NL recommends that Exchange 2016 and 2019 servers without ESU coverage should be accessible only from internal networks and phased out wherever possible.
Exchange Server Subscription Edition remains the current on-premises path.
For administrators maintaining older installations, CVE-2026-62911 is therefore not simply another patching task. It is another reminder that continuing to expose aging Exchange infrastructure directly to the internet carries an increasingly difficult security burden.
What Exchange administrators should do
The immediate priority is straightforward: organizations running affected Exchange installations should verify that Microsoft’s August 2026 security updates or later applicable updates have actually been installed.
Simply knowing that an update exists is not enough.
Administrators should verify the installed Exchange build and confirm successful installation rather than relying solely on assumptions about automatic patching.
Microsoft also recommends using its Exchange Server Health Checker after installing updates to confirm the server’s state and identify additional actions that may be required.
Organizations still running Exchange 2016 or 2019 should also confirm their ESU status and reconsider whether those systems need to remain publicly accessible.
For systems that cannot immediately be brought up to date, reducing external exposure can at least shrink the available attack surface while a longer-term migration is planned.

The patch gap remains a security problem
CVE-2026-62911 illustrates a familiar cybersecurity problem.
Finding and fixing a vulnerability is only part of the process. The fix has to reach the machines that need it.
Microsoft released its update in August. Security agencies have warned organizations about the flaw. Public proof-of-concept code is now available.
Yet tens of thousands of Exchange servers still appear exposed.
For attackers looking for valuable targets, corporate mail infrastructure offers an unusually attractive combination of sensitive information, trusted identities and potential access to other parts of a network.
For defenders, the response is considerably less complicated:
identify the affected servers, patch them, verify the update and remove unnecessary internet exposure.
The longer vulnerable Exchange installations remain publicly reachable, the less comfortable that window becomes.


