Exchange CVE-2026-62911: 21,899 Exposed Servers Still Unpatched as Exploit Code Circulates
> TL;DR: CVE-2026-62911 is a capture-replay authentication bypass in Exchange Server, fixed in the August 2026 Patch Tuesday and reported by Orange Tsai (DEVCORE Research Team). An attacker with basic privileges on the target server, plus user interaction, can elevate privileges and "take over the mailboxes of all Exchange users — send emails, read emails, download attachments," per Microsoft. The Dutch NCSC reported in late August that exploit code is already available online. On Tuesday, Shadowserver counted 21,899 IP addresses exposing an unpatched Exchange — about 6,200 in the United States and 5,100 in Germany.
The flaw and its context
Exchange Server 2016, 2019, and Subscription Edition (SE) are affected. The flaw was fixed on August 11 during Patch Tuesday — patched servers are protected. The problem is fleet status: nearly 22,000 fingerprinted Exchange servers remain exposed and unpatched three weeks later, even as NCSC-NL recommends installing updates "as soon as possible" and public exploit code circulates. Microsoft has not yet updated the advisory to confirmed in-the-wild exploitation, but the combination of a public exploit plus a massively unpatched fleet has rarely ended quietly on this platform.
Two calendar reminders worsen the picture. First, Exchange 2016 and 2019 only receive security updates through the Extended Security Updates (ESU) program, which ends in October 2026: those servers must be replaced or isolated. Second, the platform's history presses: since November 2021, CISA has added 20 Exchange vulnerabilities to its Known Exploited Vulnerabilities catalog, 14 of them tied to ransomware attacks. The most recent, CVE-2026-42897 (XSS on Outlook Web Access, fixed in June), was exploited in real attacks and KEV-listed in mid-May.
Why this matters to you
The mailbox remains the master key to nearly every other account. An attacker reading an organization's email intercepts password-reset links for your SaaS (CRM, HRIS, payroll tools), sensitive attachments, and live threads. For an HR or payroll SaaS vendor whose customers still operate on-premises Exchange — a frequent situation in French SMBs and mid-caps managed through MSPs — compromising one customer's Exchange server can become an attack on your own chain: admin account reset on your side via intercepted email, employee data extraction, downstream impersonation. That is exactly the cascade risk an authentication-surface audit exists to cut.
What to do
The broader lesson
Twenty Exchange vulnerabilities in KEV over five years, fourteen tied to ransomware, and yet tens of thousands of servers sit exposed and unpatched for weeks after every patch. The finding is old but this week repeats it: the window between disclosure and exploitation is measured in days, not months, and legacy on-prem surface is the slowest-moving part. If your organization (or your customers) still runs self-hosted Exchange, the question is not "should we patch" but "what exit plan toward managed mail, or a current Exchange SE, do we execute this quarter."
Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.
Related articles
Three adjacent analyses to keep exploring the same attack surface.
Zoom CVE-2026-53412: a critical account takeover in the Windows desktop client
An improper input validation flaw (CVSS 9.8) in Zoom Workplace for Windows, the VDI Client, and the Meeting SDK lets an unauthenticated attacker take over accounts via network access. Affects versions before 7.0.0. Fix available.
Bing Images CVE-2026-32194: a crafted SVG running as SYSTEM on Microsoft's servers
Two critical flaws (CVE-2026-32194, CVE-2026-32191, both CVSS 9.8) in Bing's image-processing tier let a crafted SVG execute commands as NT AUTHORITY\SYSTEM on Windows workers and root on Linux workers. Found by XBOW, fixed server-side by Microsoft in March 2026, details published July 23.
SharePoint CVE-2026-55040 + CVE-2026-63520: The RCE Chain Found by an AI Agent
Two chained flaws (JWT bypass + RCE) enable unauthenticated full takeover of on-premise SharePoint. Over 8,500 internet-facing servers exposed, public PoC exploited within 24 hours.
Sources
Related services
If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.