21,899 Exchange Servers Are Still Exposed to a Mailbox Hijack Bug
- The Mess: Nearly 22,000 Internet-facing Microsoft Exchange servers are still vulnerable to CVE-2026-62911, an authentication-bypass flaw that can let an attacker hijack Exchange mailboxes. Public exploit material is now available.
- The Damage: A successful attack can give access to users’ mailboxes, allowing attackers to read messages, download attachments and send mail as compromised users.
- The Fix: Install Microsoft’s August 2026 Exchange security update immediately and verify the exact server build. Do not assume that simply running the correct cumulative update means the server is patched.
There are still 21,899 Exchange servers on the Internet that shouldn’t be there in their current state.
That’s the latest number from Shadowserver’s Internet-wide scanning.
The problem is CVE-2026-62911, an authentication-bypass vulnerability affecting on-premises Microsoft Exchange Server.
Microsoft patched it during the August 2026 security updates.
Thousands of administrators apparently haven’t installed the fix yet.
The Bug Can Break the Authentication Boundary
Microsoft describes CVE-2026-62911 as an authentication bypass by capture-replay vulnerability.
The attacker can capture authentication traffic and replay it in a way that allows them to impersonate a legitimate user and elevate privileges.
The vulnerability has a CVSS score of 8.0.
That’s already serious.
The potential impact is worse.
Microsoft says a successful attacker can take over the mailboxes of Exchange users.
That means reading messages.
Downloading attachments.
Sending emails.
And potentially using compromised mailboxes as part of a larger attack.
Exchange Is the Target
The vulnerability affects on-premises:
- Exchange Server 2016
- Exchange Server 2019
- Exchange Server Subscription Edition
Microsoft released fixes for all affected branches in August.
The patched builds include:
Exchange 2016 CU23 — 15.1.2507.72
Exchange 2019 CU14 — 15.2.1544.44
Exchange 2019 CU15 — 15.2.1748.49
Exchange Server Subscription Edition — 15.2.2562.46
The exact build matters.
Exchange administrators should verify the installed security update rather than simply checking whether the server is running a particular cumulative-update branch.
21,899 Servers Are Still Exposed
This is what makes the story worth publishing now.
Shadowserver’s August 31 scan identified 21,899 unique IP addresses exposing vulnerable Exchange installations.
The United States accounted for roughly 6,200.
Germany followed with approximately 5,100.
Thousands more were distributed across other countries.
This isn’t an obscure laboratory configuration.
These are systems visible from the public Internet.
Germany Has a Particularly Ugly Number
Germany’s Federal Office for Information Security reportedly warned that approximately 85% of on-premises Exchange servers in Germany remained vulnerable.
That is a massive patching gap.
And Exchange isn’t some forgotten development server.
It’s email infrastructure.
Compromise the mailbox layer and attackers get access to one of the most useful sources of corporate intelligence.
Invoices.
Contracts.
Passwords.
Internal discussions.
Documents.
Reset links.
Everything people send to each other.
Public Exploit Material Is Now Available
The other reason the clock is ticking is the appearance of public exploit material.
A PoC repository targeting the vulnerability has now attracted attention and demonstrates a potential pre-authentication attack chain.
The original vulnerability was demonstrated at Pwn2Own Berlin 2026.
That doesn’t mean every vulnerable Exchange server can instantly be converted into a remote shell.
The public material describes a chain and researchers continue to debate its exact exploitability.
But defenders don’t get to choose when attackers become interested.
Once exploitation details become public, the barrier to experimentation drops.
Don’t Call It “Pre-Auth RCE” Without the Caveat
This distinction matters.
Some reports have started calling CVE-2026-62911 a pre-authentication RCE.
That’s too simplistic.
Microsoft’s official classification describes an authentication bypass / elevation-of-privilege vulnerability.
The more dangerous RCE scenario involves chaining techniques around the Exchange environment.
Bugstoday should report the distinction instead of turning every exploit chain into “critical RCE.”
The bug is serious enough without exaggeration.
Exchange 2016 and 2019 Are Already on Borrowed Time
There is another problem hiding underneath this vulnerability.
Exchange Server 2016 and Exchange Server 2019 have reached end of support.
Organizations enrolled in the Extended Security Update program can continue receiving security updates for a limited period.
Microsoft says those ESU security updates will continue through October 2026.
Organizations outside the program need to migrate to Exchange Server Subscription Edition or another supported architecture.
That makes CVE-2026-62911 more than a simple patching story.
It is also a reminder that keeping legacy Exchange exposed to the Internet is becoming increasingly difficult to justify.
Check MRSProxy
The attack surface is particularly interesting because the vulnerability involves Exchange’s MRSProxy functionality.
Administrators should review whether the relevant Exchange endpoints are unnecessarily exposed and whether authentication protections such as Extended Protection are properly configured.
Reducing Internet exposure is valuable even when the software is patched.
A server that doesn’t need to accept connections from the entire Internet shouldn’t.
Patch First, Investigate Second
If an Exchange server was vulnerable and Internet-facing, patching is only step one.
Review:
- authentication logs
- mailbox access
- unusual logins
- unexpected mailbox rules
- suspicious sent messages
- unusual attachment downloads
- NTLM authentication activity
- MRSProxy access
- administrative changes
Attackers don’t need to install malware if the mailbox itself becomes the foothold.
Sometimes the most useful persistence mechanism is simply an inbox.
The Numbers Are the Warning
The number 21,899 is more interesting than the CVSS score.
It tells us that the problem isn’t theoretical.
Thousands of organizations still have vulnerable Exchange infrastructure exposed directly to the Internet despite a patch being available.
And now public exploit material exists.
That’s a dangerous combination.
Bugstoday Opinion
Exchange vulnerabilities have a nasty habit of becoming infrastructure problems.
The mailbox isn’t just a mailbox.
It’s where corporate secrets arrive.
It’s where password-reset messages arrive.
It’s where invoices arrive.
It’s where employees discuss incidents they don’t want attackers reading.
CVE-2026-62911 doesn’t need to be called a magical “pre-auth RCE” to be dangerous.
An authentication bypass that can lead to mailbox takeover is already enough.
Bugstoday verdict: 21,899 exposed Exchange servers is not a technical curiosity. It’s a patching failure visible from the Internet. If you run on-premises Exchange, verify the exact build, apply the August security update and investigate any suspicious mailbox activity. Public exploit material means the comfortable part of the vulnerability lifecycle is already over.
Today’s Bugs. Tomorrow’s Breaches.
Sources
- Microsoft Security Response Center — CVE-2026-62911
- Microsoft Exchange Server Security Update — August 2026
- Shadowserver Foundation — Vulnerable Exchange Server Report
- Netherlands National Cyber Security Centre — Exchange Server Advisory
- Trend Micro Zero Day Initiative — Pwn2Own Berlin 2026




