Wednesday , September 23 2026
Microsoft Exchange Server

CVE-2026-62911
Nearly 22,000 Microsoft Exchange Servers are vulnerable to attack

Almost 22,000 Microsoft Exchange servers are online and still vulnerable to a flaw that lets attackers access all user mailboxes. Tracked as CVE-2026-62911 and reported by Orange Tsai from DEVCORE Research Team, this security flaw impacts Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) software.

“Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network,” Microsoft said when it patched the vulnerability during the August 2026 Patch Tuesday. “The attacker would be able to take over the mailboxes of all Exchange users, attackers can send emails, read emails, download attachments.”

Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and ‌one of three data-hosting zones in the...
Read More
AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

Anthropic prepares “Claude Money” to analyze bank account and financial data

Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
Anthropic prepares “Claude Money” to analyze bank account and financial data

GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Microsoft has not updated the CVE-2026-62911 advisory to confirm it yet, but the Netherlands National Cyber Security Centre (NCSC-NL) said last week that code to exploit the flaw is already online.

“Microsoft has made updates available to address the vulnerabilities. Install these updates as soon as possible,” NCSC-NL noted. “Exchange Server 2016 and 2019 only receive security updates via the Extended Security Updates Program (ESU). Are you using one of these versions? If so, ensure that the server is accessible only internally and replace it if possible.”

On Tuesday, Shadowserver found 21,899 IP addresses with Microsoft Exchange Server online that need updates. Most of them are in the United States (6,200) and Germany (5,100).

                                                Unpatched Exchange servers exposed online (Shadowserver)

Germany’s Federal Office for Information Security (BSI) warned on Friday (as first spotted by Heise) that about 85% of all on-premises Exchange servers in Germany are still at risk from this problem.

CVE-2026-62911 has not been reported as used in real attacks yet, but Microsoft fixed another problem in Exchange Server (CVE-2026-42897) in June. This flaw was used in XSS attacks against Outlook Web Access users. CISA added CVE-2026-42897 to its list of known flaws on May 15 and told U.S. government agencies to fix their servers in two weeks.

Since November 2021, CISA has added 20 problems with Microsoft Exchange Server to its list of security issues being used in attacks. 14 of these are linked to ransomware attacks.

In October, Microsoft said that Exchange 2016 and 2019 are no longer supported. CISA and the NSA then shared advice on making Exchange servers more secure against attacks.

Two months ago, Microsoft told customers that security updates for Exchange 2016 and Exchange 2019 will end in October 2026 under the Extended Security Update (ESU) program.

Check Also

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could …