Back to advisories

Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

A critical authentication bypass vulnerability (CVE-2026-62911) affects approximately 22,000 unpatched Microsoft Exchange servers running versions 2016, 2019, and SE. Attackers can hijack all user mailboxes on vulnerable systems. Exploit code is publicly available; active exploitation in the wild has not been confirmed yet, but the window is closing.

CRITICALAdvisorySep 01, 2026
Action required
Identify all Exchange Server 2016, 2019, and SE instances in your environment and patch immediately. In parallel, hunt for suspicious authentication patterns and mailbox access anomalies targeting these servers.
Affected products
Microsoft Exchange ServerExchange Server 2016Exchange Server 2019Exchange Server Subscription Edition (SE)Microsoft