VYPR
patchPublished Sep 1, 2026· 1 source

Thousands of Microsoft Exchange Servers Remain Unpatched Against Critical CVE-2026-62911

Over 21,000 Microsoft Exchange servers are still vulnerable to CVE-2026-62911, an authentication bypass flaw that allows attackers to impersonate users by replaying captured NTLM credentials.

A significant number of Microsoft Exchange servers worldwide, estimated at over 21,000, remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability. This flaw, disclosed by Microsoft in August 2026, poses a substantial risk to enterprise email infrastructure, allowing attackers to impersonate legitimate users and potentially gain full control over mailboxes.

Tracked as CWE-294 and carrying a CVSS score of 8.0, CVE-2026-62911 is described as an authentication bypass by capture-replay flaw. The vulnerability stems from an internet-facing MRSProxy endpoint that fails to properly enforce Extended Protection for Authentication. This oversight enables attackers to relay captured NTLM credentials from an Exchange machine account, effectively bypassing authentication mechanisms and paving the way for unauthorized access.

The vulnerability was initially demonstrated by Trend Micro's Zero Day Initiative at Pwn2Own Berlin 2026. While Microsoft initially rated the exploit maturity as 'unproven,' security researchers have since shown that it can be chained into more dangerous attack scenarios, significantly increasing its threat potential.

Several versions of Microsoft Exchange Server are affected, including Exchange Server 2016 Cumulative Update 23, Exchange Server 2019 Cumulative Updates 14 and 15, and Exchange Server Subscription Edition RTM. Microsoft released security updates to address these vulnerabilities on August 11, 2026, providing patched builds for each affected version.

Despite the availability of patches, daily internet-wide scans by the Shadowserver Foundation indicate a slow adoption rate. As of August 31, 2026, approximately 21,899 unique IP addresses were identified as vulnerable. The United States and Germany show the highest numbers of exposed servers, with thousands of instances in each country, followed by other nations including the UK, Russia, and Canada.

Shadowserver Foundation is now providing daily reports on these vulnerable instances, offering network defenders and national CERTs continuous visibility into unpatched systems within their jurisdictions. This proactive reporting aims to encourage faster remediation efforts.

Organizations running on-premises Exchange servers are urged to verify their specific build numbers, as simply having a cumulative update installed does not guarantee protection if it predates the August 2026 security update. Immediate remediation involves applying the relevant KB updates, restarting affected services, and implementing stronger authentication controls, such as TLS 1.2 or higher.

Given the public availability of exploit code, the window for opportunistic scanning to escalate into active exploitation is rapidly narrowing. Proactive patching and diligent security monitoring are crucial to prevent potential mailbox compromise and maintain the integrity of email communications.

Synthesized by Vypr AI