CVE-2026-62911 and 22,000 Unpatched Exchange Servers
Internet-facing mail servers are a durable target because they must accept connections from anywhere. A scan snapshot reported in September 2026 found roughly 22,000 Exchange servers still running a version affected by CVE-2026-62911, with Germany described as the highest-risk region in that sample.
What the reporting says
The report describes CVE-2026-62911 as a high-severity flaw in Exchange and states that no exploitation of this specific CVE had been observed at the time of writing. It also notes that Exchange has an unattractive history for defenders: since November 2021 CISA has added 20 Exchange vulnerabilities to its Known Exploited Vulnerabilities catalog, and 14 of those were linked to ransomware activity.
Two facts matter here. This particular flaw is unpatched on many internet-reachable servers, and it has not yet been used as far as the reporting indicates. The second fact is temporary, and the first one is the reason the second one can change quickly.
Why Exchange stays exposed
Three operational realities produce the gap. Mail servers hold credentials and often have broad directory integration, so the security team treats them carefully and changes them slowly. Patching usually requires a maintenance window that operations and business owners resist. And the deployment is often inherited, with cumulative updates, custom transport rules and third-party agents that make a clean upgrade risky.
None of that changes the arithmetic for an attacker who has already read the advisory.
What to do
- Determine the actual build of every Exchange server, including hybrid and edge transport roles, rather than relying on the last audit record.
- Patch the internet-facing tier first. A server behind a restrictive access path is a different problem from one that answers on port 443.
- Verify that autodiscover, Outlook Web Access, Exchange Web Services and ActiveSync endpoints are not exposed beyond what the organisation needs.
- Enable and review mailbox audit logging, sign-in telemetry and unusual transport rule changes. A mail server compromise usually appears as command execution, mailbox rule changes or new connectors rather than as a crash.
- Keep a small set of known-good administrator accounts with explicit monitoring, and rotate service credentials after any remediation.
The honest caveat
Scan-based counts describe reachable services and version fingerprints, not confirmed vulnerable configurations, and the figure in the report is a snapshot from one moment. The direction of the finding is still the useful part. A two-year backlog of exploited Exchange flaws exists in the public record, and thousands of servers still fail a basic version check. Those conditions are what make the next flaw easier to use than it should be.
References
- "22,000 Exchange servers worldwide remain unpatched against a high-severity flaw", 2 September 2026, https://view.inews.qq.com/wxn/20260902A09KSI00
- Same report republished on ZAKER, http://app.myzaker.com/article/6a97ca648e9f095041127784
- CISA Known Exploited Vulnerabilities Catalog, https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Top comments (0)