bleeping-computer · Crawled Sep 1, 2026
Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
Read original article ↗AI Summary
A high-severity authentication bypass vulnerability, CVE-2026-62911, affects unpatched Microsoft Exchange Server 2016, 2019, and Subscription Edition systems, allowing attackers with basic privileges to hijack all user mailboxes. Exploit code for this flaw is now publicly available, according to the Netherlands NCSC-NL. Despite Microsoft's patch release in August 2026, nearly 22,000 Exchange servers remain exposed online and unpatched, with the majority located in the United States and Germany. German authorities report approximately 85% of on-premises Exchange servers in Germany are still vulnerable.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.