22,000 Exchange servers still exposed to a public exploit

Published

Three weeks after Microsoft shipped the fix, roughly 22,000 on-premises Exchange servers are still reachable from the internet and still unpatched against CVE-2026-62911, according to scanning by the Shadowserver Foundation dated September 1. About 6,200 of them sit in the United States and about 5,100 in Germany.

Working exploit code for the flaw is already public. The Netherlands National Cyber Security Centre, NCSC-NL, has confirmed it.

A low bar to every mailbox on the box

CVE-2026-62911 is an authentication bypass, meaning it lets an attacker skip a check that is supposed to establish who they are. It affects Exchange Server 2016, Exchange Server 2019 and the Subscription Edition, and Microsoft rates it 8.0 out of 10. By Microsoft's own account, an attacker who already holds basic privileges can use it to take over every mailbox on the targeted server, reading and sending mail and downloading attachments. The patch went out in the August 2026 Patch Tuesday release.

The bug is not the news. The gap between the fix and the field is.

Why Exchange keeps ending up here

On-premises Exchange is built to face the internet. Outlook Web App has to be reachable for staff to use it, which in most deployments means reachable by anyone who can find it. Every new Exchange flaw therefore becomes a race between administrators applying an update and attackers scanning for the ones who have not, and the Shadowserver count is a measure of who is losing that race. Zscaler's Mark Brozek made the same argument in a September 3 write-up of the exposure data, framing the recurring problem as an architectural one rather than a patching failure.

Exchange's record here is not reassuring. IntelFusions has previously covered the ProxyLogon chain, where attempted exploitation ran into the tens of thousands of requests within weeks of disclosure. Internet-facing mail servers are found quickly, and mailboxes are worth the effort.

Patch now, then check the ESU clock

Apply the August 2026 Patch Tuesday update. Two scheduling facts sit alongside it. Exchange 2016 and 2019 are being carried by the Extended Security Update programme, and that programme ends in October 2026, after which neither version receives security fixes at all. Anyone still running those versions should confirm they are actually enrolled in ESU rather than assume the August update reached them.

Where patching cannot happen straight away, NCSC-NL's guidance is blunt: make sure the Exchange server is not reachable from the open internet until it can be. That is the control that actually closes the window, because the bypass has to reach the server's web listener before it can do anything at all.

CISA had not reported exploitation in the wild at the time of the Zscaler post. It is worth stating that precisely, because it is a statement about what has been observed and reported, not a forecast. With working exploit code circulating and 22,000 unpatched servers visible from the open internet, the absence of confirmed exploitation describes the present rather than the near future.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions