22,000 Microsoft Exchange servers still exposed to critical vulnerability
Almost 22,000 Microsoft Exchange servers worldwide remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability. The data emerges from Shadowserver Foundation's daily scans, with the United States and Germany leading the rankings with 6,200 and 5,100 unprotected servers respectively.
Quick Response
The CVE-2026-62911 vulnerability allows network privilege escalation. Microsoft released the patch on August 11, 2026, but many servers remain exposed. Working exploits are already circulating online, with a CVSS score of 8.0.
Technical details of the vulnerability
CVE-2026-62911 is classified as a critical vulnerability and described by Microsoft as "authentication bypass via capture-replay" in Microsoft Exchange Server. This allows an authorized attacker to escalate privileges on the network. The vulnerability was discovered by Orange Tsai of the DEVCORE Research Team in collaboration with Trend Micro's Zero Day Initiative.
NCSC-NL alert and circulation of exploits
The National Cyber Security Centre of the Netherlands (NCSC-NL) reported last week that a working exploit for this vulnerability is circulating online. The alert was raised despite Microsoft not yet confirming this circumstance in its advisory. NCSC-NL emphasized that the vulnerability has a CVSS score of 8.0 and urged administrators to install security updates as soon as possible.
Critical situation in Germany
The German Federal Office for Information Security (BSI) reported on August 8, 2026, on its Mastodon account that approximately 85% of on-premises Exchange servers in Germany remain vulnerable to CVE-2026-62911. The critical situation highlights how most organizations have not yet applied the necessary security patches.
Problems with outdated versions
Microsoft Exchange Server 2016 and 2019 are out of support, meaning that only customers enrolled in the Period 2 Extended Security Update (ESU) program can receive security updates released between May and October 2026. For organizations using these versions, NCSC-NL recommends making servers accessible only internally and replacing them if possible.
Previous vulnerabilities and attacks
In June 2026, Microsoft had already fixed CVE-2026-42897, another actively exploited vulnerability in Microsoft Exchange Server. This precedent highlights how Exchange servers have repeatedly been targeted by attacks in recent years, making timely updates fundamental to prevent data breaches.
Immediate actions recommended
NCSC-NL advises immediately contacting the IT administrator or IT service provider to verify the version of Exchange Server in use. For organizations that are unsure of the version used, it is essential to act quickly to avoid becoming a target of attacks based on this critical vulnerability.
Implications for corporate security
The persistence of this vulnerability in so many servers underscores the importance of proactive IT security management. Organizations must implement strict policies for security updates and consider adopting more modern and supported solutions to avoid becoming vulnerable to known threats.
Additional resources and support
Microsoft provides detailed guidelines and support through its official blog and the Microsoft Security Response Center (MSRC). IT administrators can find further information and specific instructions for applying the necessary patches to mitigate the risks associated with CVE-2026-62911.
The current situation requires immediate action by organizations using Microsoft Exchange Server. With the increasing circulation of working exploits, it is essential to update the servers as soon as possible to prevent potential security breaches and protect sensitive data.
Economic impact of Exchange vulnerabilities
The economic consequences of vulnerabilities like CVE-2026-62911 can be devastating for organizations. According to a recent study by Cybersecurity Ventures, data breaches related to unpatched servers can cost companies up to $4.45 million on average. This includes direct costs such as incident response and indirect costs such as loss of customer trust and reputational damage.
Global trends in vulnerability management
Data from the Shadowserver Foundation reveals that over 60% of vulnerable Exchange servers are located in countries with advanced economies, suggesting a systemic problem in security patch management. This trend is concerning, as it highlights a significant gap in cybersecurity strategies even in organizations that should be better prepared.
Alternative solutions for non-updated organizations
For organizations that cannot immediately update their Exchange servers, there are temporary solutions. For example, implementing next-generation firewalls and intrusion detection systems can help mitigate the risk of attacks. However, these measures do not replace patch updates, which remain the most effective solution.
Role of cybersecurity regulations
In many countries, regulations such as GDPR in Europe and CCPA in California require organizations to adopt adequate measures to protect personal data. Failure to apply security patches can be considered a violation of these regulations, exposing companies to legal sanctions and heavy fines.
Collaboration between public and private sectors
Managing critical vulnerabilities like CVE-2026-62911 requires close collaboration between the public and private sectors. Organizations like CERT-EU and NCSC-NL play a crucial role in providing timely information and technical support. Companies should leverage these resources to improve their security posture.
Case study: Past attacks on Exchange servers
In 2021, the ProxyLogon attack on Exchange servers compromised thousands of organizations worldwide. This attack exploited a vulnerability similar to CVE-2026-62911, demonstrating how unmanaged vulnerabilities can be exploited on a large scale. The lessons learned from this incident underscore the importance of a rapid and coordinated response.
Tools for vulnerability monitoring
There are several tools that IT administrators can use to monitor and manage vulnerabilities in their systems. Tools like Nessus, Qualys, and OpenVAS can help identify vulnerabilities and provide patch recommendations. Integrating these tools into IT security processes can significantly improve incident response capabilities.
Training and awareness of personnel
Training of IT personnel is fundamental to ensure that vulnerabilities are managed promptly. Continuous training programs and incident simulations can help administrators stay updated on the latest threats and develop practical skills for vulnerability management.
Implications for the security of critical infrastructures
Critical infrastructures, such as hospitals and utilities, often use Exchange servers for managing internal communications. The vulnerability of these systems can have serious consequences for public safety. It is essential that these organizations adopt rigorous security measures to protect their infrastructures.
Future prospects for Exchange server security
With the evolution of cyber threats, it is likely that new vulnerabilities will emerge in Exchange servers. Organizations must adopt a proactive approach to security, investing in advanced technologies and collaborating with security experts to predict and prevent potential attacks.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not perform real-time information activities.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the improper use of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves autonomously before making any decision.