ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)

highExploit / PoC exploited in the wildimportance 72CVE-2026-62911CVE-2026-42897
AI summary · glm-5.3-flash

About 22,000 Microsoft Exchange servers remain unpatched against critical auth bypass CVE-2026-62911 as a working exploit circulates online.

CVE-2026-62911 is a critical authentication bypass by capture-replay in Microsoft Exchange Server that allows an authorized attacker to elevate privileges over the network, with a CVSS score of 8.0. Microsoft patched the flaw on August 11, 2026, but Shadowserver Foundation scans show roughly 22,000 servers unpatched, with the US (6,200) and Germany (5,100) leading; BSI reports 85% of on-premises Exchange servers in Germany are still vulnerable. The Netherlands' NCSC-NL flagged that a working exploit is circulating, and Exchange 2016/2019 require the Extended Security Updates program for fixes.

  • Shadowserver daily scans show ~22,000 unpatched Exchange servers worldwide.
  • NCSC-NL reports a working exploit is circulating; Microsoft has not yet confirmed it.
  • Germany's BSI says 85% of on-premises Exchange servers remain vulnerable.
  • Exchange 2016/2019 fixes only via Extended Security Updates program through October 2026.
  • Microsoft fixed another actively exploited Exchange flaw, CVE-2026-42897, in June 2026.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-42897
Cross-Site Scripting in Microsoft Exchange Server Actively Exploited by Laundry Bear

CVE-2026-42897 is an improper-neutralization flaw (CWE-79) in Microsoft Exchange Server that lets an unauthenticated remote attacker perform cross-site scripting and carry out spoofing. Per the CVSS vector (AV:N/PR:N/UI:R), exploitation requires a victim to interact with attacker-controlled content — reported attacks by the Russian actor Laundry Bear (TA488) trigger when a crafted email is opened in Exchange's webmail interface (Outlook Web Access). The attacker gains the ability to spoof the victim within their webmail session, and reported intrusions show mailbox access persisting even after organizations rotate credentials. Any organization running on-premises Microsoft Exchange Server or Exchange Server Subscription Edition is potentially exposed, particularly those publishing webmail to the internet; specific affected version ranges are not provided in the available data. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2026-05-15 and carries a very high EPSS score of 71.2%, though no public proof-of-concept is known.

Do: Apply Microsoft's security update for CVE-2024-42897 to all on-premises Exchange and Exchange Subscription Edition servers per vendor guidance — no specific patch versions are provided in the available data, so consult the vendor advisory for build numbers. Federal agencies must patch or apply mitigations per BOD 22-01 given the KEV listing. Because reported attacks (Laundry Bear/TA488) maintain mailbox access after password resets, treat any suspected compromise as persistent: review OWA access logs and inbox rules for anomalies, and invalidate active webmail sessions and tokens, not just credentials.

6.171% KEV
  • Microsoft Exchange Server
  • Microsoft Exchange Server Subscription Edition
large≈20,000+ internet-exposed Exchange servers (public-scan reporting)
CVE-2026-62911
Capture-Replay Authentication Bypass in Microsoft Exchange Server

Microsoft Exchange Server contains an authentication bypass flaw (CWE-294) in which captured authentication material can be replayed, allowing an authorized attacker to elevate privileges over a network. Per the CVSS vector, the attack is network-based with low complexity but requires the attacker to already hold low privileges and some user interaction, and success yields high impact on confidentiality, integrity, and availability. Affected products include on-premises Exchange Server and Exchange Server Subscription Edition, though specific vulnerable version ranges are not specified in the available data. Public scans indicate nearly 22,000 Exchange servers remain exposed to the flaw following the August 2026 Patch Tuesday fixes. No in-the-wild exploitation, public proof-of-concept, or KEV listing is known; the bug was demonstrated at Pwn2Own (ZDI-26-534) and carries an EPSS estimate of 1.3% probability of exploitation within 30 days.

Do: Apply the Exchange Server security updates released in Microsoft's August 2026 Patch Tuesday (refer to Microsoft's advisory for the exact fixed builds) on all on-premises servers, prioritizing internet-facing systems running OWA, EWS, or ActiveSync. Until patched, limit network exposure of Exchange endpoints to trusted networks and monitor authentication logs for replay-style anomalies; per the scan data, roughly 22,000 servers still need the update.

8.01%
  • microsoft exchange server
  • microsoft exchange server subscription edition
large≈22,000 internet-exposed Exchange servers
Full article317 words · extracted from helpnetsecurity.com · click to collapse

Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans from the Shadowserver Foundation.

Microsoft Exchange CVE-2026-62911

The United States and Germany top the list with 6,200 and 5,100 unpatched servers.

CVE-2026-62911 is a critical severity vulnerability, and Microsoft describes it as “authentication bypass by capture-replay in Microsoft Exchange Server,” which allows an authorized attacker to elevate privileges over a network.

Microsoft released the fix on August 11, 2026, and credits Orange Tsai of the DEVCORE Research Team, working with Trend Micro’s Zero Day Initiative, for the discovery.

Although Microsoft has not yet confirmed this in its advisory, the National Cyber Security Centre of the Netherlands (NCSC-NL) flagged last week that a working exploit for the vulnerability is now circulating online.

“Multiple serious vulnerabilities have been found in Microsoft Exchange Server. One of these vulnerabilities is CVE-2026-62911, with a CVSS score of 8.0,” NCSC-NL warned.

“Microsoft has made updates available to address the vulnerabilities. Install these updates as soon as possible,” NCSC-NL noted. “Exchange Server 2016 and 2019 only receive security updates via the Extended Security Updates Program (ESU). Are you using one of these versions? If so, ensure that the server is accessible only internally and replace it if possible.”

“Don’t know which version of Exchange Server your organization uses? Then contact your IT administrator or IT service provider,” NCSC-NL aded.

Germany’s Federal Office for Information Security (BSI) wrote on its Mastodon account on August 28, 2026, that around 85 percent of on-premises Exchange servers in the country remain vulnerable to CVE-2026-62911.

In June 2026, Microsoft fixed CVE-2026-42897, an actively exploited Microsoft Exchange Server vulnerability.

“Exchange Server 2016 and 2019 are out of support. Only customers who enrolled in the Period 2 Extended Security Update (ESU) program are eligible to receive Exchange Server 2016 and 2019 security updates released between May and October 2026,” Microsoft said on its blog.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/09/02/microsoft-exchange-cve-2026-62911-critical-authentication-bypass-flaw/