Updated
Updated · linkedin · Sep 2
21,899 Exchange Servers Remain Exposed to CVE-2026-62911 as Public Exploit Code Emerges
Updated
Updated · linkedin · Sep 2

21,899 Exchange Servers Remain Exposed to CVE-2026-62911 as Public Exploit Code Emerges

3 articles · Updated · linkedin · Sep 2

Summary

  • 21,899 internet-facing Microsoft Exchange servers were still showing vulnerable fingerprints between Aug. 27 and Aug. 31, weeks after Microsoft issued an Aug. 11 patch for CVE-2026-62911.
  • CVE-2026-62911 is an authentication-bypass flaw rated 8.0/10 that can let attackers seize all mailboxes on an affected server; Dutch authorities warned the wider attack chain could also enable remote code execution.
  • 6,200 exposed systems were in the United States and about 5,100 in Germany, where BSI said roughly 85% of detected on-premises Exchange servers had not yet been protected.
  • Orange Tsai demonstrated the Exchange compromise at Pwn2Own Berlin 2026, chaining three bugs to gain SYSTEM privileges and win $200,000, underscoring that the risk is practical rather than theoretical.
  • Microsoft had not marked the flaw as exploited as of Sept. 1, but public proof-of-concept code and Exchange's history of rapid weaponization raise pressure on organizations to patch, restrict internet exposure and accelerate migration from Exchange 2016 and 2019 before ESU coverage ends in October 2026.

Insights

With thousands of servers still unpatched, how can organizations detect if attackers have already exploited this Exchange flaw to steal data?
Why did a hidden architectural mismatch in Exchange leave thousands of global networks vulnerable to complete takeover without a password?

CVE-2026-62911: The September 2026 Microsoft Exchange Exposure Crisis and Why 22,000 Servers Remain Unpatched

Overview

In September 2026, a critical vulnerability (CVE-2026-62911) in Microsoft Exchange Server, discovered by Orange Tsai, triggered a global cybersecurity crisis. Despite Microsoft releasing patches, many organizations delayed updates due to the technical complexity of enabling Extended Protection for Authentication (EPA). As a result, nearly 22,000 Exchange servers remained unpatched and exposed online, with Germany especially hard hit. The situation worsened when a public exploit was released, allowing attackers to easily gain SYSTEM-level access by chaining NTLM relay attacks through the vulnerable MRSProxy endpoint. Organizations running unsupported Exchange versions without security updates now face long-term exposure and urgent pressure to migrate or patch.

...