22,000 Microsoft Exchange servers still open to mailbox takeover flaw
A patched but widely ignored bug lets attackers read, send and download every user's email. Exploit code is already circulating.

Key points
- Around 21,899 Microsoft Exchange servers remain unpatched and reachable from the internet, according to Shadowserver data cited on Tuesday.
- The bug, CVE-2026-62911, lets an attacker with a low-level account take over every mailbox on the server.
- Microsoft shipped the fix in its August 2026 Patch Tuesday update.
- The Dutch national cyber agency NCSC-NL says working exploit code is already online.
- The United States has the most exposed servers (about 6,200), followed by Germany (about 5,100).
Here is another Exchange story where the patch exists, the exploit exists, and roughly 22,000 servers are still sitting on the internet waiting.
The flaw is CVE-2026-62911, an authentication bypass in Microsoft Exchange Server. In plain English: a hacker who has any low-level account on the server can trick it into treating them as someone far more important, and then rifle through everyone's email. Microsoft says the attacker can "take over the mailboxes of all Exchange users" and "send emails, read emails, download attachments."
It was found by Orange Tsai of DEVCORE, a researcher with a long track record of shredding Exchange. Microsoft patched it in the August 2026 Patch Tuesday release. That was months ago.
How bad is it in practice?
Bad, because the barrier to entry is low. The attacker needs an existing account on the target, but that is exactly what phishing, where criminals send fake emails to trick staff into handing over passwords, delivers every day. Once inside, the failure mode here is total: every mailbox on the box is readable and writable by the attacker.
The Netherlands National Cyber Security Centre said last week that exploit code is already circulating publicly, as first reported by BleepingComputer. Microsoft has not yet updated its advisory to flag active exploitation, but that gap between "exploit exists" and "Microsoft confirms it is being used" is usually where the ugly weekends happen.
Who is still exposed?
Shadowserver, a non-profit that scans the internet for exposed systems, counted 21,899 Exchange servers still vulnerable on Tuesday. The United States leads with roughly 6,200. Germany is next at about 5,100.
| Detail | Value |
|---|---|
| CVE | CVE-2026-62911 |
| Affected | Exchange 2016, 2019, Subscription Edition |
| Patched | August 2026 Patch Tuesday |
| Exposed servers | ~21,899 |
| Top country | United States (~6,200) |
A chunk of those servers is running Exchange 2016 or 2019, which are past end of support. Patches only reach them through Microsoft's paid Extended Security Update program, and even that lifeline ends in October 2026. NCSC-NL's advice is blunt: if you are running one of these versions, take it off the public internet and plan the replacement now.
Should ordinary users worry?
If your employer runs its own Exchange mail server, yes, a bit. An attacker who gets in can send email that looks exactly like it came from your boss, your finance team or your IT desk, because it actually did come from that mailbox. Treat urgent payment requests and password reset prompts with more suspicion than usual over the next few weeks, especially if they arrive by email alone.
Cloud Microsoft 365 mailboxes are not affected by this specific bug.
The wider pattern
CISA has added 20 Exchange vulnerabilities to its Known Exploited Vulnerabilities catalog since November 2021. Fourteen of those have shown up in ransomware, the malicious software that locks a company's files until a payment is made. Another Exchange bug from earlier this year, CVE-2026-42897, was already being abused against Outlook Web Access users before CISA ordered federal agencies to patch it in May.
One thing the post-mortem will say, again: the patch was available, the exploit was public, and the server was on the internet.
Operational takeaway: if your Exchange box is reachable from the open internet and you have not applied the August 2026 update, you are the target audience for whoever is holding that exploit.



