Overview
Cybersecurity researchers have warned that nearly 22,000 Microsoft Exchange servers remain exposed online and unpatched against a critical flaw, CVE‑2026‑62911, which allows attackers to hijack all user mailboxes. The vulnerability, reported by Orange Tsai of DEVCORE, affects Exchange Server 2016, 2019, and Subscription Edition (SE).
Vulnerability Details
- CVE‑2026‑62911: Authentication bypass via capture‑replay.
- Impact: Attackers with basic privileges can elevate access, hijack mailboxes, send/read emails, and download attachments.
- Patch release: Microsoft addressed the flaw in August 2026 Patch Tuesday.
Exploit Availability
- Exploit code online: The Netherlands NCSC confirmed exploit code is publicly available.
- Shadowserver findings: 21,899 IPs still vulnerable, with most in the U.S. (6,200) and Germany (5,100).
- BSI warning: Germany’s Federal Office for Information Security reports ~85% of on‑prem Exchange servers remain unpatched.
Broader Context
- Recent exploitation: CVE‑2026‑42897 was exploited in June via XSS attacks on Outlook Web Access.
- CISA involvement: Added CVE‑2026‑42897 to its Known Exploited Vulnerabilities Catalog in May.
- Exchange history: Since 2021, CISA has flagged 20 Exchange vulnerabilities, 14 linked to ransomware.
- End of support: Exchange 2016 and 2019 updates end in October 2026, even under ESU.
Defensive Guidance
Organizations should:
- Apply patches immediately: Install Microsoft’s August 2026 updates.
- Restrict server access: Ensure Exchange servers are accessible only internally.
- Replace legacy versions: Migrate away from Exchange 2016/2019 before ESU ends.
- Monitor mailbox activity: Detect unauthorized email access or suspicious attachments.
- Follow NSA/CISA hardening guidance: Apply recommended configurations to reduce attack surface.
Expert in the Cloud Insight
The sheer number of unpatched Exchange servers highlights a persistent challenge: critical enterprise infrastructure left exposed long after fixes are available. With exploit code already circulating, attackers can weaponize CVE‑2026‑62911 for mass mailbox hijacking. The lesson is clear: patch discipline and migration planning are non‑negotiable for organizations relying on Exchange.
Leave a Reply