CVE-2026-62911 in Exchange Server: Public Exploit Increases Pressure to Update

Microsoft fixed the critical CVE-2026-62911 vulnerability in on-premises versions of Exchange Server. NCSC-NL warns of a publicly available exploit, while Shadowserver recorded 21,899 publicly accessible IP addresses with a fingerprint of vulnerable Exchange Server.

CVE-2026-62911 in Exchange Server is a critical privilege escalation vulnerability that Microsoft fixed in its August security updates. It affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition. The Dutch National Cyber Security Centre, NCSC-NL, urged organizations to install the fixes promptly and warned that a publicly available exploit exists.

According to data from the Shadowserver Foundation, 21,899 publicly accessible IP addresses with a fingerprint of vulnerable Exchange Server were visible on the internet on September 1. This number is not a direct count of organizations or definitive confirmation that every server identified this way lacks the fix. It is the result of external internet scanning, which has limitations.

CVE-2026-62911 in Exchange Server Allows Mailbox Takeover

Microsoft classifies the flaw as a privilege escalation issue. An authorized attacker who already has basic privileges can carry out a capture-replay network attack. This could result in the takeover of users’ mailboxes.

In practice, this type of access could allow an attacker to read emails, download attachments, or send messages on behalf of compromised users. Exchange servers are therefore a sensitive target: they process internal corporate communications, and mailbox contents may include data useful for further intrusion or convincing phishing campaigns.

An important limitation is the requirement for authorized access with basic privileges. The available information does not indicate that the vulnerability allows an unauthorized attacker to immediately take over any server directly from the internet without prior access.

Fixes Are Available, and the Exploit Is Public

The fix for CVE-2026-62911 is included in Microsoft’s security updates. Organizations operating the affected on-premises versions of Exchange Server should verify the deployment status of these updates and prioritize their installation according to their own change-management procedures.

The urgency is increased by the fact that, according to NCSC-NL, a publicly available exploit already exists. Public code can simplify both testing and potential exploitation of the flaw by other actors. However, neither Microsoft nor NCSC-NL confirmed in the sources used that CVE-2026-62911 has been exploited in real-world attacks. Mass active exploitation has therefore not been confirmed.

Nearly 22,000 Systems Visible to the Public

On September 1, Shadowserver recorded 21,899 publicly accessible IP addresses with a fingerprint of vulnerable Exchange Server. This type of measurement is a useful indicator of exposure, but it should be interpreted cautiously. One organization may use multiple IP addresses, and fingerprinting may not reliably determine the exact update status of a specific system.

For administrators, the key point is not to rely on public scans as a substitute for an internal inventory. What matters is verifying whether the organization operates Exchange Server 2016, 2019, or Subscription Edition, and then checking whether the relevant security updates have been applied.

What to Watch Next

Further developments will show whether Microsoft designates CVE-2026-62911 as an actively exploited vulnerability. Attention will also turn to any potential addition of the flaw to the U.S. CISA’s Known Exploited Vulnerabilities catalog, new Shadowserver data, and technical details of the public exploit. Alerts from national cybersecurity authorities will also be relevant.

Sources

  • Microsoft Security Response Center – Microsoft’s primary record for CVE-2026-62911 and the availability of the security fix.
  • NCSC-NL – Confirms the severity of the issue, the existence of a public exploit, and the recommendation to update without delay.
  • Shadowserver Foundation – Basis for estimating the number of publicly visible Exchange servers identified as unpatched.
  • BleepingComputer – Consolidates Microsoft’s statement, the NCSC-NL warning, and current Shadowserver data.

Verified and updated: 09/01/2026 15:11

Sharing