21,000+ Microsoft Exchange Servers Remain Exposed to Active CVE-2026-62911 Exploitation
Brief
Nearly 22,000 Microsoft Exchange servers worldwide are still running unpatched for CVE-2026-62911 , a critical authentication-bypass vulnerability that attackers can exploit to seize control of enterprise email infrastructure.
According to daily internet-wide scans published by the Shadowserver Foundation, exactly 21,899 unique IP addresses were flagged as vulnerable as of August 31, 2026, underscoring how slowly organizations are responding to one of this year’s most consequential Patch Tuesday disclosures.
CVE-2026-62911 Microsoft Exchange
CVE-2026-62911 is classified as an authentication bypass by capture-replay flaw, tracked under CWE-294, and carries a CVSS score of 8.0.
