Back to blog
MicrosoftCVEAuthentification

Exchange CVE-2026-62911: 21,899 Exposed Servers Still Unpatched as Exploit Code Circulates

Published on 2026-09-015 min readCleanIssue

> TL;DR: CVE-2026-62911 is a capture-replay authentication bypass in Exchange Server, fixed in the August 2026 Patch Tuesday and reported by Orange Tsai (DEVCORE Research Team). An attacker with basic privileges on the target server, plus user interaction, can elevate privileges and "take over the mailboxes of all Exchange users — send emails, read emails, download attachments," per Microsoft. The Dutch NCSC reported in late August that exploit code is already available online. On Tuesday, Shadowserver counted 21,899 IP addresses exposing an unpatched Exchange — about 6,200 in the United States and 5,100 in Germany.

The flaw and its context

Exchange Server 2016, 2019, and Subscription Edition (SE) are affected. The flaw was fixed on August 11 during Patch Tuesday — patched servers are protected. The problem is fleet status: nearly 22,000 fingerprinted Exchange servers remain exposed and unpatched three weeks later, even as NCSC-NL recommends installing updates "as soon as possible" and public exploit code circulates. Microsoft has not yet updated the advisory to confirmed in-the-wild exploitation, but the combination of a public exploit plus a massively unpatched fleet has rarely ended quietly on this platform.

Two calendar reminders worsen the picture. First, Exchange 2016 and 2019 only receive security updates through the Extended Security Updates (ESU) program, which ends in October 2026: those servers must be replaced or isolated. Second, the platform's history presses: since November 2021, CISA has added 20 Exchange vulnerabilities to its Known Exploited Vulnerabilities catalog, 14 of them tied to ransomware attacks. The most recent, CVE-2026-42897 (XSS on Outlook Web Access, fixed in June), was exploited in real attacks and KEV-listed in mid-May.

Why this matters to you

The mailbox remains the master key to nearly every other account. An attacker reading an organization's email intercepts password-reset links for your SaaS (CRM, HRIS, payroll tools), sensitive attachments, and live threads. For an HR or payroll SaaS vendor whose customers still operate on-premises Exchange — a frequent situation in French SMBs and mid-caps managed through MSPs — compromising one customer's Exchange server can become an attack on your own chain: admin account reset on your side via intercepted email, employee data extraction, downstream impersonation. That is exactly the cascade risk an authentication-surface audit exists to cut.

What to do

  • Install the August 2026 updates on all Exchange servers, including via the ESU program for 2016/2019 — it is the only real protection against CVE-2026-62911.
  • Take 2016/2019 servers off the Internet if the move to Exchange SE is not finalized: NCSC-NL is explicit that these versions must be internal-only and replaced before the ESU program ends in October 2026.
  • Check your exposure: scan your public IP ranges for Exchange fingerprints (Shadowserver's dashboard is a free source) and treat every occurrence as an unmanaged asset.
  • Audit OWA logs for unusual authentications: capture-replay leaves traces of abnormal use of existing accounts, not logins from zero.
  • The broader lesson

    Twenty Exchange vulnerabilities in KEV over five years, fourteen tied to ransomware, and yet tens of thousands of servers sit exposed and unpatched for weeks after every patch. The finding is old but this week repeats it: the window between disclosure and exploitation is measured in days, not months, and legacy on-prem surface is the slowest-moving part. If your organization (or your customers) still runs self-hosted Exchange, the question is not "should we patch" but "what exit plan toward managed mail, or a current Exchange SE, do we execute this quarter."

    Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.

    Sources

    Written by CleanIssue
    Reviewed on 2026-09-01

    Related services

    If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.

    Need an external review of your HR SaaS?

    Share your product, stack, and client context. We will come back with the right review scope.

    Discuss your audit