22,000 Exchange Servers Unpatched for Critical Flaw
Nearly 22,000 Microsoft Exchange servers are still vulnerable to a critical patched flaw, CVE-2026-62911, for which a working exploit is now online.

Nearly 22,000 Microsoft Exchange servers globally remain unpatched against a critical authentication bypass vulnerability tracked as CVE-2026-62911. Daily scans from the Shadowserver Foundation reveal the ongoing exposure, with the United States and Germany hosting the highest numbers of vulnerable systems.
The software giant describes CVE-2026-62911 as an "authentication bypass by capture-replay in Microsoft Exchange Server." The flaw allows an authenticated attacker to elevate their privileges over a network. The company released a security update to address the vulnerability on August 11, 2026.
Vulnerability Scope and Patch Status
The Shadowserver Foundation's data shows a significant concentration of unpatched servers in two countries. Germany's Federal Office for Information Security (BSI) provided a stark national assessment on August 28, 2026, stating that approximately 85 percent of on-premises Exchange servers in Germany remain vulnerable.
| Country | Unpatched Servers |
|---|---|
| United States | 6,200 |
| Germany | 5,100 |
The tech firm credited Orange Tsai of the DEVCORE Research Team, working with Trend Micro's Zero Day Initiative, for discovering the flaw. The National Cyber Security Centre of the Netherlands (NCSC-NL) assigned the vulnerability a CVSS score of 8.0, confirming its critical severity.
Exploit Development and Warnings
Although the advisory has not yet confirmed active exploitation, the NCSC-NL warned last week that a functional exploit for CVE-2026-62911 is now circulating online. "Multiple serious vulnerabilities have been found in Microsoft Exchange Server," the Dutch agency stated, highlighting this specific flaw.
The agency urged immediate action. "Microsoft has made updates available to address the vulnerabilities. Install these updates as soon as possible," the NCSC-NL noted. This warning follows the active exploitation of a different Exchange Server vulnerability, CVE-2026-42897, which was patched in June 2026.
Guidance for Out-of-Support Versions
The update landscape is complicated for organizations running older Exchange Server versions. The vendor clarified that Exchange Server 2016 and 2019 are out of mainstream support. Security updates for these versions between May and October 2026 are only available to customers enrolled in the Period 2 Extended Security Update (ESU) program.
The NCSC-NL provided specific guidance for these older systems. "Exchange Server 2016 and 2019 only receive security updates via the Extended Security Updates Program (ESU). Are you using one of these versions?" For administrators unsure of their version, the agency advised contacting their IT administrator or service provider.
Organizations must apply the August 2026 patch immediately to close the authentication bypass. The combination of widespread unpatched systems and a publicly available exploit significantly raises the risk of compromise. The German BSI's Mastodon post highlights the urgent need for remediation in one of the most affected nations.





