ZeroHour
Zscaler ThreatLabzpublished ()ingested Mark Brozek (Senior Director, Product Marketing)2

Microsoft Exchange Vulnerability CVE-2026-62911: What Administrators Should Do and How Zscaler Can Help

AI summary · glm-5.3-flash

High-severity authentication bypass CVE-2026-62911 in Exchange Server has public exploit code; about 22,000 servers remain unpatched and internet-exposed.

Microsoft's August 2026 Patch Tuesday fixed CVE-2026-62911 (CVSS 8.0), an authentication bypass affecting Exchange Server 2016, 2019 and Subscription Edition. Successful exploitation lets an attacker with basic privileges take over all mailboxes on the targeted server, including reading and sending email and downloading attachments. As of September 1, Shadowserver identified roughly 22,000 unpatched, internet-exposed Exchange servers, including about 6,200 in the US and 5,100 in Germany. NCSC-NL confirmed working exploit code is publicly available, while CISA has not yet reported exploitation in the wild.

  • Patch shipped in August 2026 Patch Tuesday; Exchange 2016/2019 ESU ends October 2026
  • Exploitation grants takeover of all mailboxes on the targeted server
  • NCSC-NL advises keeping Exchange unreachable from the open internet until patched
  • Zscaler recommends Zero Trust access (ZPA) to eliminate inbound exposure on port 443

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-62911
Capture-Replay Authentication Bypass in Microsoft Exchange Server

Microsoft Exchange Server contains an authentication bypass flaw (CWE-294) in which captured authentication material can be replayed, allowing an authorized attacker to elevate privileges over a network. Per the CVSS vector, the attack is network-based with low complexity but requires the attacker to already hold low privileges and some user interaction, and success yields high impact on confidentiality, integrity, and availability. Affected products include on-premises Exchange Server and Exchange Server Subscription Edition, though specific vulnerable version ranges are not specified in the available data. Public scans indicate nearly 22,000 Exchange servers remain exposed to the flaw following the August 2026 Patch Tuesday fixes. No in-the-wild exploitation, public proof-of-concept, or KEV listing is known; the bug was demonstrated at Pwn2Own (ZDI-26-534) and carries an EPSS estimate of 1.3% probability of exploitation within 30 days.

Do: Apply the Exchange Server security updates released in Microsoft's August 2026 Patch Tuesday (refer to Microsoft's advisory for the exact fixed builds) on all on-premises servers, prioritizing internet-facing systems running OWA, EWS, or ActiveSync. Until patched, limit network exposure of Exchange endpoints to trusted networks and monitor authentication logs for replay-style anomalies; per the scan data, roughly 22,000 servers still need the update.

8.01%
  • microsoft exchange server
  • microsoft exchange server subscription edition
large≈22,000 internet-exposed Exchange servers
Full article1,290 words · extracted from zscaler.com · click to collapse

Zscaler Blog

Get the latest Zscaler blog updates in your inbox

Microsoft's August 2026 Patch Tuesday 

included a fix

for CVE-2026-62911, a high-severity authentication bypass vulnerability affecting Exchange Server 2016, 2019, and Subscription Edition. The severity has a CVSS score of 8.0 from Microsoft. 

As of September 1, threat intelligence group Shadowserver has identified around 22,000 Exchange servers that remain unpatched and exposed to the internet, including roughly 6,200 in the United States and 5,100 in Germany alone. 

According to Microsoft, successful exploitation allows an attacker with basic privileges to take over all mailboxes on the targeted server, including reading and sending email and downloading attachments. The Netherlands National Cyber Security Centre (NCSC-NL) has confirmed that working exploit code is already publicly available.

If you're running an on-premises Exchange server, this post outlines practical steps you can take now, and a longer-term architectural approach worth considering.

First: Apply the Patch

The August 2026 Patch Tuesday update addresses CVE-2026-62911 directly. If you haven't applied it yet, that's the first priority.

A few important notes for older versions:

  • Exchange 2016 and 2019 are on the Extended Security Update (ESU) program, which ends in October 2026. If you're on either version, confirm you're enrolled in ESU and apply the update. After October, these versions will no longer receive security fixes.
  • If patching isn't immediately possible, NCSC-NL's guidance is to ensure the Exchange server is not reachable from the open internet until the patch can be applied.

The Structural Issue: Internet Exposure

Patching is essential, but it's worth understanding why private application servers such as Exchange are repeatedly in this position. On-premises Exchange runs as an internet-facing service by design. Outlook Web App (OWA) needs to be accessible to users, which typically means it's reachable from the public internet. That reachability is what makes each new CVE a high-stakes race between patching and exploitation.

The NCSC-NL guidance to ensure Exchange is "accessible only internally" points at the right solution, but doesn't prescribe how to get there for organizations that still need to support remote access.

Why This Matters More in 2026 Than It Did in Prior Years

At the time of writing, CISA has not reported exploitations in the wild as of yet. But there's a meaningful shift in the threat landscape that makes this type of exposure a more pressing issue than it once was.

Earlier AI models gave attackers tools to automate reconnaissance. Today's frontier models, such as Anthropic's Mythos, represent a step change beyond that. They can identify a known vulnerability, develop a working exploit, and execute an attack in minutes, not days.

The practical implication: the window between a CVE being disclosed and exploitation at scale has compressed significantly. Our ThreatLabz 2026 Frontier AI Readiness Report showcased how the mean-time-to-exploit has actually gone negative – with attackers finding and exploiting vulnerabilities before they’re even disclosed. With CVE-2026-62911, exploit code is already public. An organization's ability to outpace exploitation through patching alone is less reliable than it used to be, particularly for internet-exposed infrastructure.

A Zero Trust Approach: Don’t Expose Exchange to the Internet

Zscaler Private Access (ZPA) allows organizations to eliminate the exposure of all private apps to internet-based attacks. This includes services like Exchange, which remain fully accessible to your users while being completely invisible to the internet. The way it works:

  • Managed devices: The Zscaler client routes OWA traffic through an encrypted ZPA tunnel to the Exchange server. There's no inbound connection to the server from the internet, and nothing for an attacker to probe or target.
  • Unmanaged devices: ZPA Clientless Access provides a secure, authenticated, browser-based path for users on personal or partner devices, without requiring a VPN or opening any inbound ports.

Image

The fundamental difference from a traditional VPN is how and when access is granted. A VPN establishes a persistent, always-on network tunnel — once connected, a user has broad network-level access regardless of what they're actually doing. ZPA works differently: rather than maintaining a standing tunnel, it brokers short-lived, application-specific connections on demand, and only after identity and policy checks pass. Each session is purpose-built for a specific application, time-bound by policy, and torn down once the session ends — there's no residual network foothold. A VPN gateway or concentrator is itself exposed to the internet and a frequent attacker target; ZPA has no equivalent surface, because there's nothing listening for inbound connections to begin with.

If your Exchange server is behind ZPA, CVE-2026-62911 is effectively not exploitable from the internet, regardless of whether you've patched, because the authentication bypass requires reaching port 443 on the Exchange server in the first place.

For Servers That May Already Be Compromised

If you have reason to believe a server may have been compromised before patching, additional controls are worth considering:

  • Zscaler Data Security (DLP) can inspect outbound traffic from Exchange infrastructure, helping detect data exfiltration or other malicious activity that might indicate a server has been compromised.
  • Zscaler Deception places honeypots throughout your environment that provide high-fidelity signals that an attack is underway. With their multi-path reasoning, frontier AI models are particularly likely to trip over these decoys.
  • Zscaler Cloud Workload Segmentation limits lateral movement, preventing an attacker who has gained a foothold on an Exchange server from moving to other parts of your environment.

Longer-Term: The Case for Migrating to Microsoft 365

On-premises Exchange has been one of the most consistently targeted enterprise applications over the past several years. CISA has added 20 Exchange Server vulnerabilities to its Known Exploited Vulnerabilities catalog since November 2021; 14 of those have been linked to ransomware. With Exchange 2016 and 2019 losing security update support in October 2026, the risk profile for organizations still running those versions is only going to grow.

Whether an organization utilizes on-premise solutions like Exchange or SaaS environments like Microsoft 365, private applications will always remain a baseline necessity for maintaining data confidentiality, restricted access, and regulatory compliance.

For organizations evaluating their options, migration to Microsoft 365 removes the on-premises attack surface entirely. It's not the right move for everyone on every timeline, but it's worth including in the planning conversation while investing in architectures that would empower them to respond to vulnerabilities in real-time. 

Priority

Action

Immediate

Apply the August 2026 Patch Tuesday update

Immediate

If patching is delayed, ensure Exchange is not internet-accessible

Near-term

Deploy ZPA to broker all OWA access (managed and unmanaged devices)

Near-term

Enable outbound inspection on Exchange traffic

Consider

Deploy Workload Segmentation to contain potential lateral movement

Consider

Deploy Deception to contain potential lateral movement

Consider

Deploy AppShield to virtually patch exploits

Strategic

Evaluate Microsoft 365 migration, especially if running Exchange 2016/2019

To learn more about how Zscaler can help you reduce exposure and prevent exploitation by frontier AI models, watch our on-demand webinar

form submtited

Thank you for reading

Disclaimer: This blog post has been created by Zscaler for informational purposes only and is provided "as is" without any guarantees of accuracy, completeness or reliability. Zscaler assumes no responsibility for any errors or omissions or for any actions taken based on the information provided. Any third-party websites or resources linked in this blog post are provided for convenience only, and Zscaler is not responsible for their content or practices. All content is subject to change without notice. By accessing this blog, you agree to these terms and acknowledge your sole responsibility to verify and use the information as appropriate for your needs.

Explore more Zscaler blogs

Digital map with data streaming

Securing Data in the AI Era: Insights from the ThreatLabz 2025 Data@Risk Report

Can AI Detect and Mitigate Zero Day Vulnerabilities?

Can AI Detect and Mitigate Zero Day Vulnerabilities?

What to Look for in a Deception Technology Solution

What to Look for in a Deception Technology Solution

Get the latest Zscaler blog updates in your inbox

By submitting the form, you are agreeing to our privacy policy.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.zscaler.com/blogs/security-research/microsoft-exchange-vulnerability-cve-2026-62911-what-administrators-should