Nearly 22,000 Microsoft Exchange servers remain vulnerable to CVE-2026-62911 as telemetry and working exploits circulate globally.
Telemetry data collected through daily scans by the Shadowserver Foundation indicates that approximately 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability impacting enterprise deployments.
Geographical telemetry shows that the United States and Germany maintain the highest concentrations of exposed infrastructure, accounting for 6,200 and 5,100 unpatched Microsoft Exchange servers respectively. Discovered by Orange Tsai of the DEVCORE Research Team in collaboration with Trend Micro’s Zero Day Initiative, the flaw was formally addressed by Microsoft on August 11, 2026.
Microsoft officially characterizes CVE-2026-62911 as an authentication bypass vulnerability driven by capture-replay mechanisms within Microsoft Exchange Server, enabling authorized attackers to escalate network privileges. While Microsoft’s initial advisories did not confirm active exploitation, the National Cyber Security Centre of the Netherlands (NCSC-NL) issued warnings noting that functional exploit code is currently circulating online with a CVSS score of 8.0.
Furthermore, Germany’s Federal Office for Information Security (BSI) reported via Mastodon that roughly 85 percent of on-premises Exchange servers nationwide remained unmitigated. NCSC-NL reiterated that organizations running legacy deployments such as Exchange Server 2016 and 2019 must restrict access exclusively to internal networks.
“Exchange Server 2016 and 2019 only receive security updates via the Extended Security Updates Program (ESU). Are you using one of these versions? If so, ensure that the server is accessible only internally and replace it if possible,” stated the National Cyber Security Centre of the Netherlands (NCSC-NL).
Microsoft reiterated enterprise guidelines regarding platform lifecycle management, confirming that updates for Exchange Server 2016 and 2019 are restricted strictly to customers enrolled in the Period 2 Extended Security Update program spanning May through October 2026.