Nearly 22,000 Microsoft Exchange servers are still unpatched against CVE-2026-62911, a critical authentication bypass flaw that can let an authorized attacker elevate privileges over the network. The United States and Germany have the highest numbers of vulnerable servers, while NCSC-NL and BSI have urged immediate patching as a working exploit is reportedly circulating online. #CVE-2026-62911 #MicrosoftExchangeServer #NCSC-NL #BSI #OrangeTsai #DEVCOREResearchTeam #TrendMicroZeroDayInitiative
Keypoints
- Nearly 22,000 Microsoft Exchange servers remain vulnerable to CVE-2026-62911.
- The flaw is an authentication bypass that can enable privilege elevation over the network.
- The United States and Germany have the largest number of unpatched servers.
- NCSC-NL warned that a working exploit is now circulating online.
- Microsoft released the fix on August 11, 2026, and Exchange Server 2016 and 2019 require ESU updates.