Microsoft Exchange Servers Vulnerable

Overview

Cybersecurity researchers have warned that nearly 22,000 Microsoft Exchange servers remain exposed online and unpatched against a critical flaw, CVE‑2026‑62911, which allows attackers to hijack all user mailboxes. The vulnerability, reported by Orange Tsai of DEVCORE, affects Exchange Server 2016, 2019, and Subscription Edition (SE).

Vulnerability Details

  • CVE‑2026‑62911: Authentication bypass via capture‑replay.
  • Impact: Attackers with basic privileges can elevate access, hijack mailboxes, send/read emails, and download attachments.
  • Patch release: Microsoft addressed the flaw in August 2026 Patch Tuesday.

Exploit Availability

  • Exploit code online: The Netherlands NCSC confirmed exploit code is publicly available.
  • Shadowserver findings: 21,899 IPs still vulnerable, with most in the U.S. (6,200) and Germany (5,100).
  • BSI warning: Germany’s Federal Office for Information Security reports ~85% of on‑prem Exchange servers remain unpatched.

Broader Context

  • Recent exploitation: CVE‑2026‑42897 was exploited in June via XSS attacks on Outlook Web Access.
  • CISA involvement: Added CVE‑2026‑42897 to its Known Exploited Vulnerabilities Catalog in May.
  • Exchange history: Since 2021, CISA has flagged 20 Exchange vulnerabilities, 14 linked to ransomware.
  • End of support: Exchange 2016 and 2019 updates end in October 2026, even under ESU.

Defensive Guidance

Organizations should:

  • Apply patches immediately: Install Microsoft’s August 2026 updates.
  • Restrict server access: Ensure Exchange servers are accessible only internally.
  • Replace legacy versions: Migrate away from Exchange 2016/2019 before ESU ends.
  • Monitor mailbox activity: Detect unauthorized email access or suspicious attachments.
  • Follow NSA/CISA hardening guidance: Apply recommended configurations to reduce attack surface.

Expert in the Cloud Insight

The sheer number of unpatched Exchange servers highlights a persistent challenge: critical enterprise infrastructure left exposed long after fixes are available. With exploit code already circulating, attackers can weaponize CVE‑2026‑62911 for mass mailbox hijacking. The lesson is clear: patch discipline and migration planning are non‑negotiable for organizations relying on Exchange.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.