Nearly 22,000 Microsoft Exchange servers exposed as exploit goes public
Hackers have a tool ready to target thousands of exposed email servers.

- Shadowserver found nearly 22,000 public IPs with vulnerable Microsoft Exchange servers, mostly in the US and Germany.
- Public proof-of-concept code increases the risk that attackers will target unpatched Exchange systems.
- Attackers could take over mailboxes, read or send emails, download attachments, and move deeper into networks.
- Administrators should install updates, limit server access to internal networks, or replace unsupported Exchange servers.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Threat actors can take over the mailboxes of all Exchange users, read or send emails, and download all attachments, and the proof-of-concept code is already public. Shadowserver flags nearly 22,000 unpatched Microsoft Exchange instances, most of them in the US and Germany.
Shadowserver Foundation, a nonprofit that performs internet-wide security scans, sees “at least 21899 IPs” with Microsoft Exchange instances vulnerable to CVE-2026-62911.
This severe vulnerability “allows an unauthorized malicious person to execute arbitrary code,” according to the recently updated advisory by the Dutch National Cyber Security Center (NCSC).
Moreover, the proof-of-concept code has already been published online, prompting the NCSC to raise the priority level to “high.”
Microsoft initially disclosed the bug 3 weeks ago, on August 11th, saying that “authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.”
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
In simpler terms, attackers can reuse captured credentials.
Exchange is a business-class email, calendaring, and collaboration server developed by Microsoft. The tech giant warned that attackers can take over all mailboxes, send and read emails, and download attachments.
In the US alone, there are 6,164 vulnerable Exchange servers visible to outsiders. Germany has 5,127 exposed vulnerable IPs, followed by hundreds of IPs in the UK, Russia, Canada, Austria, France, Italy, the Netherlands, and other countries.
The problem is that Microsoft Exchange Server 2016 and 2019 have reached the end of support, and security updates are only available through the Extended Security Updates (ESU) program.
NCSC urges administrators to install updates as soon as possible, or make sure that affected servers are accessible only internally – they should be replaced whenever possible.
“Through CVE-2026-62911, an attacker can execute malicious code without remote login credentials. This allows an attacker to access email accounts and possibly penetrate further into the network,” the watchdog warned.
Microsoft patches in August addressed several additional Exchange vulnerabilities, including a heap-based buffer overflow in Microsoft Exchange Server, which allows an authorized attacker to execute code over a network.
Organizations enrolled in the Period 2 Extended Security Update (ESU) program are eligible to receive security updates until the end of October 2026. Microsoft urges them to migrate to the Exchange Server Subscription Edition to receive the latest security updates.