A serious security problem has been unfolding quietly in the background of the internet, and it is worth understanding even if you never touch a server in your life. Nearly 22,000 Microsoft Exchange servers around the world are still exposed to a critical Microsoft Exchange vulnerability that can let attackers seize control of every mailbox on an affected system — and working exploit code for it is now circulating publicly.
The flaw, tracked as CVE-2026-62911, was fixed by Microsoft back in August, yet many organizations have not applied the update. That gap between a patch existing and being installed is exactly the window attackers look for, which is why security agencies in several countries have urged affected organizations to act without delay.
The reassuring news for most readers is that this flaw mainly affects organizations running their own email servers, not everyday people on cloud email. But it still matters to all of us. Here is what the vulnerability is, who is genuinely at risk, and what to do about it.
What Is the Microsoft Exchange Vulnerability?
At its core, this Microsoft Exchange vulnerability is a critical authentication-bypass flaw in the on-premises version of Microsoft’s Exchange Server — the software many organizations use to run their own email in-house. It affects Exchange Server 2016, Exchange Server 2019, and the newer Subscription Edition, and it carries a severity rating of 8.0 out of 10, placing it firmly in the high-priority category.
What makes it so dangerous is the outcome. An attacker who exploits it can take over the mailboxes of every user on that Exchange server — reading emails, sending messages as them, and downloading attachments. For an organization, that is close to a worst-case scenario. It was found by respected researchers and responsibly disclosed, and Microsoft issued a fix in its August 2026 security updates.
The technical details of how the flaw is exploited are a matter for security professionals, not something ordinary users need — what matters here is the risk and the response. And Microsoft’s response already exists: a patch has been available for weeks. The problem, as so often, is that many servers have not received it.
Why Thousands of Servers Are Still at Risk
Despite the fix being available since August, internet-wide scans by the Shadowserver Foundation found close to 22,000 Exchange servers still unpatched at the end of the month. The United States had the most exposed systems, followed by Germany, whose cyber-security agency estimated that the large majority of its on-premises Exchange servers remained vulnerable.
The reason is simply that patching email servers across large organizations is slow, complicated work that rarely happens fast enough. These are not abandoned machines; they are live mail servers belonging to businesses, schools, and government bodies that have not yet applied the update — and that delay is what turns a fixed flaw into an ongoing risk.
That risk has sharpened recently, because the Netherlands’ national cyber-security centre reported that working proof-of-concept exploit code is now available online, prompting it to raise the threat to its high-priority level. Microsoft had not, at the time of the reports, confirmed that the flaw was being actively abused in the wild — but once reliable exploit code is public, the barrier to attack drops sharply, which is precisely why the warnings have grown louder. This is not the first time Exchange has been targeted, either; a separate flaw earlier in the year was actively exploited against Outlook Web Access users and added to the U.S. government’s catalogue of known-exploited vulnerabilities.
Who Is Actually Affected?

This is the question that matters most, and the answer is reassuring for the average person. The vulnerability affects on-premises Exchange servers — systems an organization installs and runs itself, on its own hardware. So the organizations at direct risk are businesses, institutions, and government bodies that host their own email this way, especially where those servers face the internet and are unpatched.
If your email runs on a cloud service — Microsoft 365, Outlook.com, or Exchange Online, as well as the likes of Gmail — then your provider manages the underlying servers and their security updates, and you are not exposed to this on-premises flaw in the same way. For the great majority of home users, that is the situation, and there is no server for you to patch. The people who need to act are those who run Exchange themselves, or the IT teams and service providers who look after it on an organization’s behalf.
The grey area is the workplace. Plenty of companies, schools, and smaller businesses still run their own Exchange servers, so your work email — or a small business you use — could sit on an affected system. If you are unsure what your organization uses, that is a reasonable thing to raise with whoever handles its IT.
Why It Matters Even If You Don’t Run a Server
It would be easy to read all this, conclude that you use cloud email, and move on — but the fallout from compromised mail servers has a way of reaching everyone eventually. A hijacked email system is one of the most valuable prizes an attacker can win, and the damage rarely stays contained to the organization that was breached.
The most immediate knock-on effect is phishing. When criminals control a real, trusted mailbox, they can send convincing scams from a genuine address to that person’s colleagues, customers, and contacts — which may include you. Because they come from a real account, these messages sail past the usual warning signs. Compromised servers are also a rich source of stolen data that fuels fraud down the line. The instincts that help you spot phishing scams are your best protection here.
The practical takeaway for everyone: a hijacked mail server can send convincing scams from real, trusted addresses. Treat unexpected or unusual emails with extra caution right now — even when they appear to come from someone you know.
What to Do Now
The right action depends on whether you are responsible for an Exchange server or are simply an email user. If you run, or help run, one — including at a small business — the priority is straightforward but urgent.
- Apply the August 2026 security update immediately to any Exchange Server 2016, 2019, or Subscription Edition system, following Microsoft’s official guidance and running its Exchange Health Checker afterwards to confirm the fix.
- Isolate and plan to replace older servers. Exchange 2016 and 2019 have reached the end of mainstream support and now receive fixes only through the Extended Security Updates programme, so keep internet-facing servers restricted and plan a migration where you can.
- If you are unsure what your organization runs, ask your IT team or service provider directly — it is a reasonable and important question.
If you are simply an email user, you cannot patch someone else’s server, but you are far from powerless — a few habits meaningfully reduce your exposure to the fallout.

- Turn on two-factor authentication everywhere you can, so that a stolen password alone is not enough to access your accounts. Our guide to enabling two-factor authentication walks through it.
- Be extra sceptical of email right now, even from people you know, and avoid clicking unexpected links or opening unsolicited attachments — the habits covered in our email security best practices matter more than usual.
- Watch for unusual account activity, such as unexpected sign-ins or messages you did not send, and act quickly if something looks off, as covered in our guide to preventing account takeover.
For the authoritative technical details and the patch itself, the Microsoft website has resources you may find useful, and the CISA website has resources you may find useful on this and other actively tracked vulnerabilities. This situation is also a timely reminder of why keeping software updated matters, a theme we covered around Microsoft’s recent Patch Tuesday.
Microsoft Exchange Vulnerability: Frequently Asked Questions
Am I affected if I use Outlook.com or Microsoft 365?
Generally no. This flaw affects on-premises Exchange servers that organizations run themselves. If your email is on a cloud service such as Microsoft 365, Outlook.com, or Exchange Online, the provider manages the servers and their updates, so you are not exposed to this particular vulnerability in the same way.
What is CVE-2026-62911?
It is the official identifier for this critical authentication-bypass vulnerability in Microsoft Exchange Server, rated 8.0 in severity. If exploited, it can let an attacker take over every mailbox on an affected server. Microsoft released a fix for it in its August 2026 security updates.
Is the vulnerability being exploited?
At the time of reporting, Microsoft had not confirmed active exploitation in the wild, but security agencies warned that working exploit code is now publicly available. That significantly raises the risk, which is why organizations are being urged to patch immediately rather than wait.
What should I do if my company uses Exchange?
If you help manage it, apply the August 2026 update straight away and follow Microsoft’s guidance. If you are an ordinary user, you cannot patch it yourself, but you can raise it with your IT team, enable two-factor authentication, and stay especially alert to phishing until you know it has been resolved.
A critical Microsoft Exchange vulnerability leaving tens of thousands of servers exposed is a reminder that security is only as strong as its slowest patch. Most home users are not directly in the firing line, but the phishing and data theft that follow a mail-server breach touch everyone. So if you run Exchange, update it now; if you do not, tighten your own defences and treat your inbox with a little extra suspicion.







