Microsoft Exchange CVE-2026-62911 auth bypass; ~22k internet-exposed hosts still unpatched
Microsoft patched CVE-2026-62911 in the August 2026 Patch Tuesday cycle: authentication bypass by capture-replay in Exchange Server that lets an authorised attacker elevate privileges over the network and take over user mailboxes (send, read, download attachments). Affected products named in coverage include Exchange Server 2016, 2019 and Subscription Edition. On 1 September 2026 BleepingComputer reported Shadowserver observing 21,899 internet-exposed Exchange fingerprints still unpatched (largest counts in the United States and Germany), and relayed NCSC-NL guidance that exploit code is available and that Exchange 2016/2019 security updates require the Extended Security Updates programme. Germany's BSI separately warned that a large share of on-premises Exchange in Germany remained vulnerable. This desk has not seen a CISA KEV listing for CVE-2026-62911 at write-up. NEW 8 Sep AU: iTnews cites Shadowserver counts of 382 Australian and 56 New Zealand Exchange hosts still vulnerable as of 31 August 2026; NCSC-NL (28 Aug) said public PoC exists and warned unauthenticated attackers could potentially achieve arbitrary code execution; ASD urges patching or network segmentation for legacy Exchange; coverage rates CVSS 3.1 as 8.0. Patch promptly; do not leave legacy Exchange on the public internet.
- Product
- Microsoft Exchange Server
- Versions
- Exchange Server 2016, 2019, Subscription Edition (per public coverage); confirm against MSRC
- CVSS
- 8.0 (CVSS 3.1 per iTnews/Microsoft coverage)
- Exploited in Australia?
- unknown
- Patch to
- August 2026 Exchange security update; restrict internet exposure; plan exit from ESU-era 2016/2019
Primary: Microsoft MSRC (CVE-2026-62911) · Vendor: Microsoft (vendor) · CVE: CVE-2026-62911 · iTnews — AU/NZ Shadowserver counts + PoC (8 Sep 2026); earlier BC 1 Sep
