Close Menu
NCIJ Network NCIJ Network
    What's Hot

    What to Watch in the Massachusetts Primary Election

    September 1, 2026

    5 Best Folding Phones (2026): Samsung, Google, Motorola

    September 1, 2026

    Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

    September 1, 2026
    Facebook X (Twitter) Instagram
    Trending
    • What to Watch in the Massachusetts Primary Election
    • 5 Best Folding Phones (2026): Samsung, Google, Motorola
    • Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
    • Asia Sees Digital Asset Custody Infrastructure Deals from Ripple, Coincheck
    • Mindfulness may lower blood pressure in just 8 weeks
    • In Ecuador’s Intag Valley, communities build their own micro-hydropower plant
    • How to tackle the climate impact of datacentres | Datacentres – UK
    • Is Amazon buying and destroying large amounts of books to train AI? Unpacking the claim
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 1
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 1, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes.

    Tracked as CVE-2026-62911 and reported by DEVCORE Research Team’s Orange Tsai, this security flaw affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) software. Threat actors with basic privileges on the targeted server can exploit it in low-complexity attacks that require user interaction.

    “Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network,” Microsoft said when it patched the vulnerability during the August 2026 Patch Tuesday. “The attacker would be able to take over the mailboxes of all Exchange users, attackers can send emails, read emails, download attachments.”

    While Microsoft has yet to update the CVE-2026-62911 advisory to confirm it, the Netherlands National Cyber Security Centre (NCSC-NL) reported last week that exploit code for this vulnerability is already available online.

    “Microsoft has made updates available to address the vulnerabilities. Install these updates as soon as possible,” NCSC-NL noted. “Exchange Server 2016 and 2019 only receive security updates via the Extended Security Updates Program (ESU). Are you using one of these versions? If so, ensure that the server is accessible only internally and replace it if possible.”

    On Tuesday, threat security watchdog group Shadowserver said that it found 21,899 IP addresses with a Microsoft Exchange Server fingerprint that are still unpatched and exposed online, most of them in the United States (6,200) and Germany (5,100).

    Unpatched Exchange servers exposed online
    Unpatched Exchange servers exposed online (Shadowserver)

    Germany’s Federal Office for Information Security (BSI) also warned on Friday (as first spotted by Heise) that around 85% of all on-premises Exchange servers in Germany are still vulnerable to this vulnerability.

    While CVE-2026-62911 has yet to be flagged as abused in the wild, Microsoft patched another Exchange Server vulnerability (CVE-2026-42897) in June that was exploited in cross-site scripting (XSS) attacks targeting Outlook Web Access users.

    The Cybersecurity and Infrastructure Security Agency (CISA) also added the CVE-2026-42897 flaw to its Known Exploited Vulnerabilities Catalog on May 15 and ordered U.S. government agencies to patch their servers within two weeks.

    Since November 2021, CISA has added 20 Microsoft Exchange Server vulnerabilities to its list of actively exploited security issues, 14 of them also flagged as abused in ransomware attacks.

    In October, after Microsoft announced that Exchange 2016 and 2019 had reached the end of support, CISA and the National Security Agency (NSA) released joint guidance on hardening Exchange servers against attacks.

    Two months ago, Microsoft also reminded customers that Exchange 2016 and Exchange 2019 security updates will stop shipping through the Extended Security Update (ESU) program in October 2026.

    Update September 01, 08:58 EDT: Added BSI warning.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    attacks Exchange hijack Microsoft Servers vulnerable
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hackers Start Exploiting Critical Langflow Vulnerability

    Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

    Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

    Israeli attacks on Gaza kill at least four, including children | Gaza News

    9.5 Million Impacted by Aesto Health Data Breach

    Recently patched PaperCut zero-days used in data theft attacks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    What to Watch in the Massachusetts Primary Election

    September 1, 2026

    5 Best Folding Phones (2026): Samsung, Google, Motorola

    September 1, 2026

    Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

    September 1, 2026

    Asia Sees Digital Asset Custody Infrastructure Deals from Ripple, Coincheck

    September 1, 2026
    Latest Posts

    Bitcoin Only Makes Up 1% Of Legendary Investor Ray Dalio’s Portfolio

    July 30, 2026

    AI Harnesses Burst With Potential Exploit Opps

    July 30, 2026

    LinkedIn actually adds a ‘seems like AI slop’ button

    July 30, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    What to Watch in the Massachusetts Primary Election

    September 1, 2026

    5 Best Folding Phones (2026): Samsung, Google, Motorola

    September 1, 2026

    Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

    September 1, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.