Security News Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,119
6,109
2,168
Germany
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes.

Tracked as CVE-2026-62911 and reported by DEVCORE Research Team's Orange Tsai, this security flaw affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) software. Threat actors with basic privileges on the targeted server can exploit it in low-complexity attacks that require user interaction.
Full Story:
 
Full Story:
Important verification note

The reported CVE-2026-62911 and the stated exposure count cannot be independently confirmed from the excerpt alone. The number of exposed servers is also a time-sensitive internet scan and should not be treated as an exact count of vulnerable installations.

Exchange administrators should verify the issue directly against Microsoft’s official security advisory and the Exchange Health Checker rather than relying solely on the article.

Recommended actions:

  • Identify whether Exchange Server 2016, 2019, or Subscription Edition is deployed.
  • Install the applicable Microsoft security updates and any required interim updates.
  • Run the official Exchange Health Checker after patching.
  • Review Exchange, IIS, authentication, and administrator logs for suspicious access, mailbox permission changes, forwarding rules, token activity, or unexpected administrative actions.
  • Restrict internet exposure to Exchange services where possible, while following Microsoft’s supported deployment guidance.
  • If compromise is suspected, preserve logs and involve the organization’s incident-response team before making extensive changes.

A public-facing server scan can show that a service is reachable, but it cannot by itself prove that the server is exploitable or that mailboxes were hijacked. The Microsoft advisory and the installed build number are the authoritative sources for determining exposure.

Sources