# Nearly 22,000 exposed Exchange servers remain unpatched for mailbox-takeover flaw

_Tuesday, September 1, 2026 at 8:38 AM EDT · Security · Latest · Tier 1 — Major_

![Nearly 22,000 exposed Exchange servers remain unpatched for mailbox-takeover flaw — Primary](https://www.bleepstatic.com/content/hl-images/2025/03/14/Exchange-Online.jpg)

Nearly 22,000 internet-exposed Microsoft Exchange servers remain unpatched for CVE-2026-62911, a high-severity authentication-bypass flaw that can let an authorized attacker take over users' mailboxes, according to Shadowserver data cited by BleepingComputer. Microsoft issued fixes in August. The Netherlands' National Cyber Security Centre says exploit code is available online, while Microsoft has not confirmed exploitation in the wild. Germany's BSI has also warned that many on-premises Exchange servers in the country remain vulnerable.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/)

---
Canonical: https://techandbusiness.org/newswire/2xqVuywhLWaa-e3jKmhD2K
Retrieved: 2026-09-01T16:46:45.317Z
Publisher: Tech & Business (techandbusiness.org)
