The critical vulnerability CVE-2026-62911 (CVSS 8.0 HIGH) is an authentication bypass by capture-replay in Microsoft Exchange Server, allowing authorized attackers to elevate privileges over a network. It affects Microsoft Exchange Server 2016, and the fixed version is 15.02.2562.046. Despite the patch being available, nearly 22,000 servers globally remain unpatched.
Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans from the Shadowserver Foundation. The United States and Germany top the list with 6,200 and 5,100 unpatched servers. CVE-2026-62911 is a critical severity vulnerability, and Microsoft describes it as “authentication bypass by capture-replay in Microsoft Exchange Server,” which allows an authorized attacker to elevate privileges over a network. Microsoft released the fix on August 11, 2026, and … More → The post Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) appeared first on Help Net Security .