Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

All IT Services security alert — 22,000 Microsoft Exchange servers still exposed to CVE-2026-62911 authentication bypass

Nearly 22,000 Microsoft Exchange servers worldwide are still unpatched against CVE-2026-62911, a critical authentication bypass that lets an attacker with basic network access take over every mailbox on the server — reading emails, sending as any user, and downloading attachments.

Microsoft patched the flaw on 11 August, but Shadowserver’s scan on 31 August found 21,899 servers still exposed — most in the US and Germany, but the vulnerability affects Exchange 2016, 2019, and Subscription Edition everywhere. Exploit code is already circulating, and the Dutch NCSC has urged immediate patching.

Why This Matters for Australian Businesses

We still find on-prem Exchange servers in Australian environments more often than you’d expect. The usual story: a business moved most mailboxes to Microsoft 365 eighteen months ago but left a hybrid connector running, or kept one server “just for calendar sync” and never finished decommissioning it. Those forgotten boxes are exactly the ones that don’t get patched — and CVE-2026-62911 only needs basic credentials and network access to escalate to full mailbox control.

With Exchange 2016 and 2019 losing security updates entirely in October, any unpatched server is already on borrowed time.

What to Do

Patch immediately. Apply the August 2026 security update to every Exchange server in your environment — including the one nobody remembers is still running.

Find the forgotten servers. Check your Entra ID for hybrid connectors that are still active. If you thought the migration was done, confirm it actually is.

Plan the exit. If you’re still running Exchange 2016 or 2019, talk to us about completing the migration to Microsoft 365 before ESU support ends in October.

If you’re not sure whether you have an Exchange server exposed, get in touch and we’ll check for you.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →