Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
21,000+ Microsoft Exchange Servers Vulnerable to Exploitation

21,000+ Microsoft Exchange Servers Vulnerable to Exploitation

Posted on September 1, 2026 By CWS

More than 21,000 Microsoft Exchange servers globally remain vulnerable to the critical CVE-2026-62911 flaw, a serious security issue allowing attackers to potentially control enterprise email systems. The Shadowserver Foundation’s recent scans have identified 21,899 unique IP addresses still exposed as of August 31, 2026, highlighting a slow response to this significant security threat.

Understanding CVE-2026-62911

CVE-2026-62911 is an authentication bypass vulnerability linked to capture-replay flaws, classified under CWE-294, with a CVSS score of 8.0. Announced by Microsoft on August 11, 2026, the vulnerability allows attackers to mimic legitimate users and escalate privileges across Exchange Server by capturing and replaying authentication traffic.

Experts have demonstrated that this vulnerability can be exploited in more severe scenarios. The flaw is associated with MRSProxy endpoints accessible via the internet, failing to implement Extended Protection for Authentication. This oversight lets attackers relay NTLM credentials, bypassing authentication and compromising mailboxes.

Impacted Products and Fixes

The vulnerability affects several versions of Exchange Server, including 2016 Cumulative Update 23, 2019 CU14 and CU15, and the Subscription Edition RTM. Microsoft has provided security updates to address these issues: 15.1.2507.72 for Exchange 2016 CU23, 15.2.1544.44 for 2019 CU14, 15.2.1748.49 for 2019 CU15, and 15.2.2562.46 for the Subscription Edition.

Despite these updates, Shadowserver’s data reveals a significant number of unpatched servers, particularly in the United States and Germany, with over 6,200 and 5,100 vulnerable servers, respectively. Other countries, including the UK, Russia, and Canada, report hundreds of exposed servers.

Recommendations for Security Teams

Organizations running on-premises Exchange servers must verify their build numbers to ensure they have the latest security patches. Immediate remediation steps include applying the relevant updates, restarting services, and implementing stronger authentication measures such as TLS 1.2 or higher. Monitoring for unusual NTLM relay activities is also recommended.

The emergence of proof-of-concept exploit codes adds urgency to patching efforts, as unpatched systems face an increasing risk of exploitation. Shadowserver continues to provide daily reports to help organizations and national CERTs monitor and manage unpatched systems within their networks.

In conclusion, timely action is crucial to prevent potential security breaches. Organizations are encouraged to integrate threat intelligence into their security operations to bolster defenses against such vulnerabilities.

Cyber Security News Tags:authentication bypass, CVE-2026-62911, Cybersecurity, Exchange Server, Microsoft Exchange, NTLM relay, patch management, security updates, Shadowserver Foundation, Vulnerability

Post navigation

Previous Post: Critical JFrog Artifactory Flaw Exploited for Admin Access
Next Post: Hackers Exploit ChatGPT Links to Deploy Malware on Windows

Related Posts

Chrome 151 Update Fixes Five Critical Security Flaws Chrome 151 Update Fixes Five Critical Security Flaws Cyber Security News
LangChainGo Vulnerability Let Attackers Access Sensitive Files LangChainGo Vulnerability Let Attackers Access Sensitive Files Cyber Security News
Chrome Security Update Patches Critical Remote Code Execution Vulnerability Chrome Security Update Patches Critical Remote Code Execution Vulnerability Cyber Security News
10 Best Enterprise Remote Access Software 10 Best Enterprise Remote Access Software Cyber Security News
AI-Powered Forg365 Platform Targets Microsoft 365 Accounts AI-Powered Forg365 Platform Targets Microsoft 365 Accounts Cyber Security News
Hackers Using Malicious Imageless QR Codes to Render Phishing Attack Via HTML Table Hackers Using Malicious Imageless QR Codes to Render Phishing Attack Via HTML Table Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit ChatGPT Links to Deploy Malware on Windows
  • 21,000+ Microsoft Exchange Servers Vulnerable to Exploitation
  • Critical JFrog Artifactory Flaw Exploited for Admin Access
  • Palo Alto Networks Expands AI Capabilities with Console Purchase
  • Hackers Exploit AI Bot Names to Steal Sensitive Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit ChatGPT Links to Deploy Malware on Windows
  • 21,000+ Microsoft Exchange Servers Vulnerable to Exploitation
  • Critical JFrog Artifactory Flaw Exploited for Admin Access
  • Palo Alto Networks Expands AI Capabilities with Console Purchase
  • Hackers Exploit AI Bot Names to Steal Sensitive Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark