A critical vulnerability, CVE-2026-62911, has left nearly 22,000 Microsoft Exchange servers worldwide unpatched and susceptible to potential exploitation. This vulnerability, identified as an authentication bypass flaw, allows attackers to impersonate legitimate users and take control of enterprise email infrastructure by capturing and replaying authentication traffic. Despite Microsoft's disclosure of this issue on August 11, 2026, and the availability of fixed builds, a significant number of servers remain exposed.

Daily scans by the Shadowserver Foundation reveal that 21,899 unique IP addresses were still vulnerable as of August 31, 2026. The United States tops the list with approximately 6,200 exposed servers, followed closely by Germany with around 5,100. Other countries, including the United Kingdom, Russia, and Canada, also report numerous instances of vulnerability.

The flaw originates from an MRSProxy endpoint that does not enforce Extended Protection for Authentication, allowing attackers to relay NTLM credentials and bypass authentication. Security teams are urged to verify their servers' build numbers and ensure they have applied the relevant August 2026 security updates. It is crucial to apply these updates, restart services, and implement stronger authentication controls to mitigate potential risks.

Shadowserver continues to provide daily reports on these vulnerabilities, delivering essential visibility for network defenders and national CERTs. With public exploit code already available, unpatched organizations are under increasing threat of exploitation.