22,000 Microsoft Exchange Servers Are Still Exposed — And the Exploit Is Public
- The Mess: Nearly 22,000 internet-facing Microsoft Exchange servers remain unpatched against CVE-2026-62911, while public proof-of-concept exploit code is already available.
- The Damage: The flaw can be used to abuse Exchange authentication and potentially give attackers access to highly sensitive enterprise email infrastructure.
- The Fix: Install Microsoft’s August 2026 Exchange security updates immediately and remove unnecessary Exchange services from direct internet exposure.
Microsoft patched the vulnerability weeks ago.
Thousands of Exchange servers are still sitting on the internet without the fix.
And now the exploit is public.
Security researchers and internet scanning data indicate that nearly 22,000 Microsoft Exchange servers remain exposed to CVE-2026-62911, a high-severity authentication-related vulnerability affecting on-premises Exchange infrastructure.
This is exactly the combination Exchange administrators never want to see:
A patch exists.
The vulnerable servers are visible from the internet.
And public exploit code has lowered the barrier for attackers.
The Password Isn’t the Main Problem
CVE-2026-62911 is not another phishing story.
The problem sits inside the way affected Exchange infrastructure handles authentication.
The vulnerability is described as an authentication bypass by capture-replay.
That means the security problem is not necessarily about guessing or stealing a user’s password.
The attack path abuses authentication traffic and trust relationships inside the Exchange environment.
That distinction matters.
Exchange servers are not ordinary web applications.
They sit near some of the most valuable data inside an organization:
- corporate email
- attachments
- internal communications
- authentication data
- administrative information
- business records
A serious Exchange compromise can become much more than an email problem.
Nearly 22,000 Servers Are Still Waiting
The patch has been available since Microsoft’s August 2026 security updates.
That did not solve the exposure problem.
Internet scanning data shows that almost 22,000 Exchange servers still appear to be running vulnerable versions.
Every exposed server creates the same opportunity.
Attackers don’t need to know which company owns the system.
They can scan the internet.
Identify Exchange.
Check the version.
Move to the next target.
At this scale, patching delays become part of the attack surface.
The Public PoC Changes the Risk
There is an important difference between a vulnerability that exists only in a vendor advisory and one with publicly available exploit material.
A public proof of concept does not automatically mean that every criminal group is exploiting the flaw.
It does mean that attackers no longer need to independently reproduce the research.
The technical barrier drops.
Testing vulnerable servers becomes easier.
Automated scanning becomes more attractive.
That is the point where an unpatched internet-facing Exchange server stops looking like ordinary patch debt.
It starts looking like a target.
Exchange Is Still a High-Value Target
Attackers keep returning to Microsoft Exchange for a simple reason.
Email infrastructure is valuable.
One compromised server can potentially provide access to:
- internal conversations
- sensitive attachments
- business intelligence
- password reset emails
- authentication workflows
- administrative systems
Exchange also has a long history of vulnerabilities becoming attractive to large-scale attackers.
That history should influence how organizations prioritize a newly public exploit.
The question is not whether every Exchange vulnerability becomes ProxyLogon.
The question is whether an organization wants to discover too late that this one became the next major campaign.
Old Exchange Deployments Make Everything Worse
CVE-2026-62911 affects on-premises Exchange deployments, including Exchange Server 2016, Exchange Server 2019 and Exchange Server Subscription Edition.
Microsoft has released security updates for affected supported configurations.
But Exchange 2016 and Exchange 2019 create an additional problem.
Both products have reached end of support, and organizations relying on them need Extended Security Updates or migration to continue receiving security fixes.
That means some organizations are no longer dealing with a simple:
Click update.
They may be dealing with:
Buy extended support or migrate critical infrastructure.
Attackers don’t care which option is inconvenient.
Public Exposure Is the First Thing to Check
The most urgent question for administrators is simple:
Is this Exchange server reachable from the internet?
If the answer is yes, the patch should not wait for the next maintenance cycle.
Organizations should identify:
- all internet-facing Exchange servers
- forgotten secondary servers
- disaster-recovery systems
- legacy deployments
- exposed management endpoints
Large environments often have more Exchange infrastructure than administrators remember.
Attackers are good at finding the systems nobody remembered to patch.
Patching Is Not the Only Step
Installing the security update closes the known vulnerability.
It does not prove that nobody attempted to exploit the server before the patch was installed.
Organizations running an exposed vulnerable Exchange server should also review:
- unusual authentication activity
- unexpected NTLM events
- suspicious mailbox access
- unexpected ASPX files
- unexplained changes to Exchange configuration
- unusual administrative activity
- unexpected outbound connections
If suspicious activity appears, this stops being a patch-management problem.
It becomes an incident-response problem.
Exchange Online Is Not the Same Target
The issue affects on-premises Microsoft Exchange Server infrastructure.
Organizations that have completely moved their email environment to Exchange Online are not affected by the vulnerable on-premises component.
Hybrid environments are more complicated.
If an organization still maintains on-premises Exchange infrastructure, that infrastructure still needs to be checked.
Cloud migration does not help the server you forgot to turn off.
The Patch Window Is Shrinking
The vulnerability was fixed before public exploit material became widely available.
That gave defenders an advantage.
For a while.
Now that technical exploitation information is circulating, that advantage is smaller.
The usual vulnerability timeline applies:
Disclosure.
Patch.
Public research.
Scanning.
Exploitation.
Organizations want to disappear from that sequence somewhere near step two.
Not step five.
What Exchange Administrators Should Do Now
If your organization runs on-premises Exchange:
- Identify every Exchange server.
- Check whether the August 2026 security updates are installed.
- Prioritize internet-facing systems immediately.
- Run Microsoft’s Exchange Health Checker.
- Review logs for suspicious activity before and after patching.
- Remove unnecessary Exchange endpoints from public exposure.
- Plan migration if you still depend on Exchange versions approaching the end of their security-update path.
The number of exposed servers is large.
That does not make an individual vulnerable server safer.
It makes attackers more likely to automate the search.
Bugstoday Opinion
Exchange administrators have seen this pattern before.
A serious vulnerability gets patched.
Thousands of servers remain exposed.
Then exploit code appears.
At that point, waiting for confirmed mass exploitation is a terrible strategy.
Public exploit code is already enough of a warning.
Bugstoday verdict: Nearly 22,000 exposed Exchange servers are not just a patch-management statistic. They are a ready-made target list. If your server is on it, patch first and ask questions later.
Today’s Bugs. Tomorrow’s Breaches.
Sources
- Microsoft — Exchange Server August 2026 Security Updates
- Microsoft — CVE-2026-62911
- Shadowserver Foundation
- NCSC-NL
- CVE.org




