Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)
PoC publicMicrosoft Exchange ServerOur summary
A working exploit for CVE-2026-62911 has appeared online, leaving nearly 22,000 instances of Microsoft Exchange Server vulnerable to a critical authentication bypass. This flaw allows attackers to elevate privileges over the network, with the United States and Germany reporting the highest concentration of unpatched systems. Microsoft issued a fix on August 11, 2026, following disclosure by Orange Tsai in collaboration with Trend Micro’s Zero Day Initiative.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.