More than 21,000 Microsoft Exchange servers globally remain vulnerable to the critical CVE-2026-62911 flaw, a serious security issue allowing attackers to potentially control enterprise email systems. The Shadowserver Foundation’s recent scans have identified 21,899 unique IP addresses still exposed as of August 31, 2026, highlighting a slow response to this significant security threat.
Understanding CVE-2026-62911
CVE-2026-62911 is an authentication bypass vulnerability linked to capture-replay flaws, classified under CWE-294, with a CVSS score of 8.0. Announced by Microsoft on August 11, 2026, the vulnerability allows attackers to mimic legitimate users and escalate privileges across Exchange Server by capturing and replaying authentication traffic.
Experts have demonstrated that this vulnerability can be exploited in more severe scenarios. The flaw is associated with MRSProxy endpoints accessible via the internet, failing to implement Extended Protection for Authentication. This oversight lets attackers relay NTLM credentials, bypassing authentication and compromising mailboxes.
Impacted Products and Fixes
The vulnerability affects several versions of Exchange Server, including 2016 Cumulative Update 23, 2019 CU14 and CU15, and the Subscription Edition RTM. Microsoft has provided security updates to address these issues: 15.1.2507.72 for Exchange 2016 CU23, 15.2.1544.44 for 2019 CU14, 15.2.1748.49 for 2019 CU15, and 15.2.2562.46 for the Subscription Edition.
Despite these updates, Shadowserver’s data reveals a significant number of unpatched servers, particularly in the United States and Germany, with over 6,200 and 5,100 vulnerable servers, respectively. Other countries, including the UK, Russia, and Canada, report hundreds of exposed servers.
Recommendations for Security Teams
Organizations running on-premises Exchange servers must verify their build numbers to ensure they have the latest security patches. Immediate remediation steps include applying the relevant updates, restarting services, and implementing stronger authentication measures such as TLS 1.2 or higher. Monitoring for unusual NTLM relay activities is also recommended.
The emergence of proof-of-concept exploit codes adds urgency to patching efforts, as unpatched systems face an increasing risk of exploitation. Shadowserver continues to provide daily reports to help organizations and national CERTs monitor and manage unpatched systems within their networks.
In conclusion, timely action is crucial to prevent potential security breaches. Organizations are encouraged to integrate threat intelligence into their security operations to bolster defenses against such vulnerabilities.
