Tuesday , September 1 2026
Microsoft Exchange Server

CVE-2026-62911
Nearly 22,000 Microsoft Exchange Servers are vulnerable to attack

Almost 22,000 Microsoft Exchange servers are online and still vulnerable to a flaw that lets attackers access all user mailboxes. Tracked as CVE-2026-62911 and reported by Orange Tsai from DEVCORE Research Team, this security flaw impacts Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) software.

“Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network,” Microsoft said when it patched the vulnerability during the August 2026 Patch Tuesday. “The attacker would be able to take over the mailboxes of all Exchange users, attackers can send emails, read emails, download attachments.”

CVE-2026-62911
Nearly 22,000 Microsoft Exchange Servers are vulnerable to attack

Almost 22,000 Microsoft Exchange servers are online and still vulnerable to a flaw that lets attackers access all user mailboxes. Tracked...
Read More
CVE-2026-62911  Nearly 22,000 Microsoft Exchange Servers are vulnerable to attack

CISA alerts on multiple PaperCut NG/MF flaws being actively exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has listed two flaws in PaperCut NG and PaperCut MF in its...
Read More
CISA alerts on multiple PaperCut NG/MF flaws being actively exploited

Fire Ant hackers convert Cisco routers into spy platforms

The researchers discovered Fire Ant's new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco...
Read More
Fire Ant hackers convert Cisco routers into spy platforms

Five Critical WordPress Flaws Lead to Site Takeover or RCE

Many serious security flaws have been found in WordPress plugins and themes, such as WPMU DEV Dashboard, Avada, TranslatePress, Pods,...
Read More
Five Critical WordPress Flaws Lead to Site Takeover or RCE

700 AI agents united to hack Hugging Face after breaking isolation

700 AI agents supposedly escaped their isolation, created a secret communication channel, and worked together to attack Hugging Face's systems....
Read More
700 AI agents united to hack Hugging Face after breaking isolation

ServiceNow warns of three critical security vulnerabilities

ServiceNow issued security updates for three new serious AI Platform problems that can be used in code injection, SQL injection,...
Read More
ServiceNow warns of three critical security vulnerabilities

100+ Tech and Security Orgs Urge Global Cyber Defense Boost Against AI Threats

Over 100 tech, cybersecurity, and finance groups have signed an open letter with OpenAI. They want a global increase in...
Read More
100+ Tech and Security Orgs Urge Global Cyber Defense Boost Against AI Threats

8.7 Million Customers data exposed from 3 Airports 

3 airports in the UK were affected by a "cyber security incident." Hackers got into data belonging to nearly nine...
Read More
8.7 Million Customers data exposed from 3 Airports 

Crack 85 Accounts and Steal 2,500+ Records
8-Agent AI Framework Used to Compromise Gov’t Entities in Asia

A cyberattack using open-source AI tools almost ran on its own. It affected government systems in Asia, compromised into 85...
Read More
Crack 85 Accounts and Steal 2,500+ Records  8-Agent AI Framework Used to Compromise Gov’t Entities in Asia

270+ Zimbra servers compromised in continuous attacks

Threat actors have already compromised more than 270 Zimbra instances in attacks that let them run code remotely. These attacks...
Read More
270+ Zimbra servers compromised in continuous attacks

Microsoft has not updated the CVE-2026-62911 advisory to confirm it yet, but the Netherlands National Cyber Security Centre (NCSC-NL) said last week that code to exploit the flaw is already online.

“Microsoft has made updates available to address the vulnerabilities. Install these updates as soon as possible,” NCSC-NL noted. “Exchange Server 2016 and 2019 only receive security updates via the Extended Security Updates Program (ESU). Are you using one of these versions? If so, ensure that the server is accessible only internally and replace it if possible.”

On Tuesday, Shadowserver found 21,899 IP addresses with Microsoft Exchange Server online that need updates. Most of them are in the United States (6,200) and Germany (5,100).

                                                Unpatched Exchange servers exposed online (Shadowserver)

Germany’s Federal Office for Information Security (BSI) warned on Friday (as first spotted by Heise) that about 85% of all on-premises Exchange servers in Germany are still at risk from this problem.

CVE-2026-62911 has not been reported as used in real attacks yet, but Microsoft fixed another problem in Exchange Server (CVE-2026-42897) in June. This flaw was used in XSS attacks against Outlook Web Access users. CISA added CVE-2026-42897 to its list of known flaws on May 15 and told U.S. government agencies to fix their servers in two weeks.

Since November 2021, CISA has added 20 problems with Microsoft Exchange Server to its list of security issues being used in attacks. 14 of these are linked to ransomware attacks.

In October, Microsoft said that Exchange 2016 and 2019 are no longer supported. CISA and the NSA then shared advice on making Exchange servers more secure against attacks.

Two months ago, Microsoft told customers that security updates for Exchange 2016 and Exchange 2019 will end in October 2026 under the Extended Security Update (ESU) program.

Check Also

ServiceNow

ServiceNow warns of three critical security vulnerabilities

ServiceNow issued security updates for three new serious AI Platform problems that can be used …