Nearly 22,000 Microsoft Exchange Servers Remain Unpatched for Critical CVE-2026-62911 Vulnerability
As of August 31, 2026, 21,899 Microsoft Exchange servers worldwide remain unpatched for CVE-2026-62911, a critical authentication-bypass vulnerability that allows attackers to seize control of enterprise email systems. The flaw, disclosed by Microsoft on August 11, 2026, enables privilege escalation by exploiting an MRSProxy endpoint that fails to enforce Extended Protection for Authentication (EPA), permitting NTLM credential relay attacks.
Classified under CWE-294 with a CVSS score of 8.0, the vulnerability was first demonstrated at Pwn2Own Berlin 2026 by Trend Micro’s Zero Day Initiative, which contested Microsoft’s initial exploit-maturity assessment. If exploited, attackers can bypass authentication entirely, leading to full mailbox compromise.
Affected versions include:
- Exchange Server 2016 CU23 (patched in 15.1.2507.72)
- Exchange Server 2019 CU14 & CU15 (patched in 15.2.1544.44 and 15.2.1748.49, respectively)
- Exchange Server Subscription Edition RTM (patched in 15.2.2562.46)
Global Exposure & Risk
Internet-wide scans by the Shadowserver Foundation reveal the U.S. (6,200 vulnerable servers) and Germany (5,100) as the most exposed, followed by the U.K., Russia, Canada, Austria, and France. Smaller clusters appear in Italy, the Netherlands, China, and other regions.
Shadowserver now provides daily vulnerability reports, enabling defenders and CERTs to track unpatched systems. With public proof-of-concept exploit code circulating, organizations face a narrowing window before opportunistic attacks escalate. Security teams are advised to verify build numbers and apply the August 2026 security updates immediately.
Source: https://cybersecuritynews.com/exchange-servers-remain-exposed-2026-62911/
Microsoft TPRM report: https://www.rankiteo.com/company/microsoft-security-response-center
"id": "mic1788267525",
"linkid": "microsoft-security-response-center",
"type": "Vulnerability",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Technology/Enterprise',
'location': 'Global',
'name': 'Microsoft Exchange Server Users',
'size': '21,899 unpatched servers',
'type': 'Software/Service'}],
'attack_vector': 'Authentication Bypass (NTLM Credential Relay)',
'customer_advisories': 'Organizations using Microsoft Exchange Server urged '
'to patch CVE-2026-62911 to prevent unauthorized '
'access.',
'data_breach': {'personally_identifiable_information': 'Potential (if '
'exploited)',
'sensitivity_of_data': 'High (enterprise communications, PII '
'potential)',
'type_of_data_compromised': 'Email data, mailbox contents'},
'date_detected': '2026-08-11',
'date_publicly_disclosed': '2026-08-11',
'description': 'As of August 31, 2026, 21,899 Microsoft Exchange servers '
'worldwide remain unpatched for CVE-2026-62911, a critical '
'authentication-bypass vulnerability that allows attackers to '
'seize control of enterprise email systems. The flaw enables '
'privilege escalation by exploiting an MRSProxy endpoint that '
'fails to enforce Extended Protection for Authentication '
'(EPA), permitting NTLM credential relay attacks.',
'impact': {'data_compromised': 'Full mailbox compromise',
'identity_theft_risk': 'High (if exploited)',
'operational_impact': 'Potential unauthorized access to enterprise '
'email systems',
'systems_affected': 'Microsoft Exchange Servers (21,899 '
'unpatched)'},
'investigation_status': 'Ongoing (vulnerability tracking and patching '
'efforts)',
'lessons_learned': 'Importance of timely patching for critical '
'vulnerabilities, especially in enterprise email systems. '
'Need for Extended Protection for Authentication (EPA) '
'enforcement.',
'post_incident_analysis': {'corrective_actions': 'Patch vulnerable Exchange '
'Server versions and enforce '
'EPA.',
'root_causes': 'Failure to enforce Extended '
'Protection for Authentication '
'(EPA) in MRSProxy endpoint, '
'leading to NTLM credential relay '
'attacks.'},
'recommendations': 'Immediately verify Exchange Server build numbers and '
'apply August 2026 security updates. Monitor Shadowserver '
'Foundation reports for unpatched systems. Enforce EPA to '
'mitigate NTLM relay risks.',
'references': [{'source': 'Microsoft Security Update'},
{'source': 'Shadowserver Foundation'},
{'source': 'Pwn2Own Berlin 2026 (Trend Micro’s Zero Day '
'Initiative)'}],
'response': {'communication_strategy': 'Public advisories and daily '
'vulnerability reports',
'containment_measures': 'Apply August 2026 security updates',
'enhanced_monitoring': 'Shadowserver Foundation tracking',
'remediation_measures': 'Patch vulnerable Exchange Server '
'versions (CU23, CU14, CU15, '
'Subscription Edition RTM)',
'third_party_assistance': 'Shadowserver Foundation '
'(vulnerability scans)'},
'stakeholder_advisories': 'Security teams advised to verify build numbers and '
'apply patches immediately.',
'title': 'Nearly 22,000 Microsoft Exchange Servers Remain Unpatched for '
'Critical CVE-2026-62911 Vulnerability',
'type': 'Vulnerability Exploitation',
'vulnerability_exploited': 'CVE-2026-62911 (CWE-294)'}