Skip to main content
HIGH Vulnerabilities #Authentication Bypass

CVE-2026-62911: Exchange Servers Vulnerable to Mailbox Hijack

4 min read Runtime Rebel Intel
Primary source: bleepingcomputer.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • Nearly 22,000 unpatched Microsoft Exchange servers are exposed to potential mailbox hijack attacks.
  • Microsoft Exchange Server 2016, 2019, and Subscription Edition (SE) are vulnerable to CVE-2026-62911.
  • Immediately apply the August 2026 Patch Tuesday updates to mitigate the authentication bypass flaw.

Advertisement

Urgent Threat: Thousands of Exchange Servers Exposed to Mailbox Hijack

Nearly 22,000 Microsoft Exchange servers worldwide remain unpatched against a high-severity authentication bypass vulnerability, CVE-2026-62911, that could allow attackers to fully hijack user mailboxes. This flaw, enabling privilege elevation, poses a significant risk to organizations still operating vulnerable versions of Exchange Server exposed to the internet. While in-the-wild exploitation for this specific CVE has not yet been confirmed, public exploit code is reportedly available, significantly increasing the urgency for immediate patching, according to BleepingComputer.

Understanding CVE-2026-62911: Authentication Bypass in Microsoft Exchange Server

Tracked as CVE-2026-62911, this security vulnerability was reported by DEVCORE Research Team’s Orange Tsai. It affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) software. Microsoft describes it as an “Authentication bypass by capture-replay” that permits an authorized attacker to elevate privileges over a network. This means that an attacker, even with basic privileges on the targeted server, could perform low-complexity attacks that initially require user interaction to gain a foothold. Once exploited, the attacker can take over the mailboxes of all Exchange users, allowing them to send emails, read emails, and download attachments. This represents a complete compromise of communication within the affected organization.

Microsoft addressed this flaw during its August 2026 Patch Tuesday. However, recent warnings from the Netherlands National Cyber Security Centre (NCSC-NL) indicate that exploit code for CVE-2026-62911 is already publicly accessible. Further emphasizing the widespread exposure, the security watchdog group Shadowserver reported that 21,899 IP addresses with a Microsoft Exchange Server fingerprint are still unpatched and openly accessible online. A significant portion of these vulnerable servers are located in the United States (6,200) and Germany (5,100).

Broader Context: Persistent Threats to Exchange Environments

This vulnerability is not an isolated incident but rather part of a persistent trend of threats targeting Microsoft Exchange infrastructure. For example, in June, Microsoft patched another Exchange Server vulnerability, CVE-2026-42897, which was actively exploited in cross-site scripting (XSS) attacks impacting Outlook Web Access users. The Cybersecurity and Infrastructure Security Agency (CISA) added this flaw to its Known Exploited Vulnerabilities Catalog on May 15, mandating U.S. government agencies to patch their servers within two weeks. Since November 2021, CISA has listed 20 Microsoft Exchange Server vulnerabilities in its catalog of actively exploited security issues, with 14 of those also linked to ransomware attacks. This history underscores the critical importance of keeping Exchange servers fully updated and secured.

Furthermore, Microsoft has announced that Exchange 2016 and 2019 reached their end of support, and security updates will cease shipping through the Extended Security Update (ESU) program in October 2026. This end-of-life status for older versions further complicates the security posture for organizations that have not yet migrated, making patching Microsoft Exchange Server 2016 CVE-2026-62911 and other critical updates even more urgent.

Actionable Recommendations for Mitigating Exchange Server Authentication Bypass

Given the severity and accessibility of exploit code for CVE-2026-62911, organizations must prioritize remediation efforts. Here are key actions defenders should take:

  • Immediate Patching: Apply the August 2026 Patch Tuesday updates to all Microsoft Exchange Server installations without delay. This is the single most effective action to prevent exploitation of CVE-2026-62911.
  • Address End-of-Life Systems: For organizations still utilizing Exchange Server 2016 and 2019, which only receive security updates via the Extended Security Updates (ESU) program, NCSC-NL advises ensuring these servers are accessible only internally. Replacing these versions with a supported solution should be a strategic priority. This directly impacts the mitigating Exchange Server authentication bypass risks.
  • Review CISA Known Exploited Vulnerabilities Catalog: Regularly consult the CISA Known Exploited Vulnerabilities Catalog for critical updates on actively exploited flaws, especially those impacting Microsoft Exchange. Prioritize patching for all listed vulnerabilities.
  • Harden Exchange Servers: Implement the joint guidance released by CISA and the National Security Agency (NSA) on hardening Exchange servers against attacks. This guidance provides comprehensive recommendations for improving the overall security posture of these critical systems.
  • Network Segmentation and Monitoring: Implement network segmentation to limit external exposure of Exchange servers. Continuously monitor server logs for any unusual activity, authentication anomalies, or signs of compromise, which could indicate attempts to exploit vulnerabilities like CVE-2026-62911.

Related: CVE-2024-21319: PeopleSoft Auth Bypass Exploited by ShinyHunters, CVE-2026-0257: Palo Alto Networks PAN-OS GlobalProtect Bypass Active

Advertisement

Advertisement